« Volver al listado

Qualcomm

Qualcomm Qca6584 Firmware: vulnerabilidades y CVE

Qualcomm Qca6584 Firmware tiene 149 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 41 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE149
Últimos 12 meses2
Críticas41
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47320Alta (7.8)0.08%—18 dic 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-47318Alta (7.5)0.21%—24 sept 2025
Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-21428Alta (7.5)0.25%—7 abr 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
CVE-2024-38426Media (5.3)0.27%—3 mar 2025
While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-38422Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-33051Alta (7.5)0.30%—2 sept 2024
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2023-43551Alta (7.5)0.26%—3 jun 2024
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2024-21468Alta (7.8)0.11%—1 abr 2024
Memory corruption when there is failed unmap operation in GPU.
CVE-2023-33066Alta (7.8)0.11%—4 mar 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-43511Alta (7.5)0.32%—2 ene 2024
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33120Alta (7.8)0.11%—2 ene 2024
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
CVE-2023-33033Alta (7.8)0.12%—2 ene 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33030Alta (7.8)0.12%—2 ene 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-28551Alta (7.8)0.12%—5 dic 2023
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
CVE-2023-28550Alta (7.8)0.12%—5 dic 2023
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
CVE-2023-33059Alta (7.8)0.11%—7 nov 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-24849Alta (7.5)0.30%—3 oct 2023
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
CVE-2023-24848Alta (7.5)0.30%—3 oct 2023
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
CVE-2023-22385Crítica (9.8)0.35%—3 oct 2023
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
CVE-2023-33020Alta (7.5)0.35%—5 sept 2023
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
CVE-2023-33019Alta (7.5)0.35%—5 sept 2023
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.
CVE-2023-28565Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
CVE-2023-28542Alta (7.8)0.12%—4 jul 2023
Memory Corruption in WLAN HOST while fetching TX status information.
CVE-2023-21628Alta (7.8)0.12%—6 jun 2023
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
CVE-2022-40521Alta (7.5)0.35%—6 jun 2023
Transient DOS due to improper authorization in Modem
CVE-2022-33264Alta (7.8)0.11%—6 jun 2023
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1068 Exploitation for Privilege Escalation2
  3. T1190 Exploit Public-Facing Application2
  4. T1499.004 Application or System Exploitation2
  5. T1041 Exfiltration Over C2 Channel1
  6. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm