« Volver al listado

Qualcomm

Qualcomm Qca9990 Firmware: vulnerabilidades y CVE

Qualcomm Qca9990 Firmware tiene 140 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 17 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE140
Últimos 12 meses2
Críticas17
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-24088Alta (8.2)0.07%—1 jun 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2025-47339Alta (7.8)0.08%—7 ene 2026
Memory corruption while deinitializing a HDCP session.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-21446Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
CVE-2025-21448Alta (7.5)0.26%—7 abr 2025
Transient DOS may occur while parsing SSID in action frames.
CVE-2024-33050Alta (7.5)0.30%—2 sept 2024
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
CVE-2024-33014Alta (7.5)0.32%—5 ago 2024
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-33012Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
CVE-2024-33011Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
CVE-2024-33010Alta (7.5)0.28%—5 ago 2024
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
CVE-2024-21459Alta (7.5)0.26%—5 ago 2024
Information disclosure while handling beacon or probe response frame in STA.
CVE-2024-23368Alta (7.8)0.10%—1 jul 2024
Memory corruption when allocating and accessing an entry in an SMEM partition.
CVE-2024-21473Crítica (9.8)0.66%—1 abr 2024
Memory corruption while redirecting log file to any file location with any file name.
CVE-2023-33105Alta (7.5)0.75%—4 mar 2024
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
CVE-2023-28578Alta (7.8)0.12%—4 mar 2024
Memory corruption in Core Services while executing the command for removing a single event listener.
CVE-2023-43536Alta (7.5)0.32%—6 feb 2024
Transient DOS while parse fils IE with length equal to 1.
CVE-2023-43522Alta (7.5)0.32%—6 feb 2024
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
CVE-2023-43511Alta (7.5)0.32%—2 ene 2024
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33116Alta (7.5)0.32%—2 ene 2024
Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.
CVE-2023-33109Alta (7.5)0.34%—2 ene 2024
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
CVE-2023-33062Alta (7.5)0.34%—2 ene 2024
Transient DOS in WLAN Firmware while parsing a BTM request.
CVE-2023-33098Alta (7.5)0.47%—5 dic 2023
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
CVE-2023-33089Alta (7.5)0.47%—5 dic 2023
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
CVE-2023-33088Alta (7.8)0.16%—5 dic 2023
Memory corruption when processing cmd parameters while parsing vdev.
CVE-2023-33083Crítica (9.8)0.61%—5 dic 2023
Memory corruption in WLAN Host while processing RRM beacon on the AP.
CVE-2023-33082Crítica (9.8)0.53%—5 dic 2023
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33063Alta (7.8)0.69%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33047Alta (7.5)0.43%—7 nov 2023
Transient DOS in WLAN Firmware while parsing no-inherit IES.
CVE-2023-28569Media (5.5)0.14%—7 nov 2023
Information disclosure in WLAN HAL while handling command through WMI interfaces.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation3
  2. T1190 Exploit Public-Facing Application3
  3. T1059 Command and Scripting Interpreter2
  4. T1499 Endpoint Denial of Service2
  5. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm