Qualcomm
Qualcomm Qca6174 Firmware: vulnerabilidades y CVE
Qualcomm Qca6174 Firmware tiene 89 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 20 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE89
Últimos 12 meses0
Críticas20
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-21438 | Alta (7.8) | 0.11% | — | 7 abr 2025 | Memory corruption while IOCTL call is invoked from user-space to read board data. |
| CVE-2025-21428 | Alta (7.5) | 0.25% | — | 7 abr 2025 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. |
| CVE-2024-43050 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. |
| CVE-2024-38423 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing GPU page table switch. |
| CVE-2024-38422 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. |
| CVE-2024-33051 | Alta (7.5) | 0.30% | — | 2 sept 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| CVE-2024-23353 | Alta (7.5) | 0.35% | — | 5 ago 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
| CVE-2023-43551 | Alta (7.5) | 0.26% | — | 3 jun 2024 | Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| CVE-2024-21468 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption when there is failed unmap operation in GPU. |
| CVE-2023-33066 | Alta (7.8) | 0.11% | — | 4 mar 2024 | Memory corruption in Audio while processing RT proxy port register driver. |
| CVE-2023-43511 | Alta (7.5) | 0.32% | — | 2 ene 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| CVE-2023-33120 | Alta (7.8) | 0.11% | — | 2 ene 2024 | Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
| CVE-2023-33033 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in Audio during playback with speaker protection. |
| CVE-2023-33080 | Alta (7.5) | 0.34% | — | 5 dic 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| CVE-2023-28550 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
| CVE-2023-33059 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-24848 | Alta (7.5) | 0.30% | — | 3 oct 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| CVE-2023-22385 | Crítica (9.8) | 0.35% | — | 3 oct 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. |
| CVE-2023-28565 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. |
| CVE-2023-28560 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. |
| CVE-2023-21628 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. |
| CVE-2022-40521 | Alta (7.5) | 0.35% | — | 6 jun 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-33264 | Alta (7.8) | 0.11% | — | 6 jun 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2023-21666 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. |
| CVE-2023-21665 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory corruption in Graphics while importing a file. |
| CVE-2022-40532 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. |
| CVE-2022-33302 | Alta (7.8) | 0.12% | — | 13 abr 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |
| CVE-2022-33289 | Media (6.8) | 0.19% | — | 13 abr 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
| CVE-2022-40531 | Alta (7.8) | 0.12% | — | 10 mar 2023 | Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message. |
| CVE-2022-33213 | Alta (8.8) | 0.41% | — | 10 mar 2023 | Memory corruption in modem due to buffer overflow while processing a PPP packet |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.