« Volver al listado

Qualcomm

Qualcomm Qts110 Firmware: vulnerabilidades y CVE

Qualcomm Qts110 Firmware tiene 72 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE72
Últimos 12 meses2
Críticas9
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-27054Alta (7.8)0.09%—9 oct 2025
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2024-38426Media (5.3)0.27%—3 mar 2025
While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33016Media (6.8)0.15%—2 sept 2024
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23359Alta (8.2)0.26%—2 sept 2024
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-21462Media (5.5)0.09%—1 jul 2024
Transient DOS while loading the TA ELF file.
CVE-2024-21461Alta (7.8)0.10%—1 jul 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2023-43551Alta (7.5)0.26%—3 jun 2024
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2023-28547Alta (7.8)0.11%—1 abr 2024
Memory corruption in SPS Application while requesting for public key in sorter TA.
CVE-2023-33066Alta (7.8)0.11%—4 mar 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-33033Alta (7.8)0.12%—2 ene 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33032Alta (7.8)0.12%—2 ene 2024
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
CVE-2023-33030Alta (7.8)0.12%—2 ene 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-28586Media (6.5)0.14%—5 dic 2023
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
CVE-2023-28585Alta (8.8)0.14%—5 dic 2023
Memory corruption while loading an ELF segment in TEE Kernel.
CVE-2023-28551Alta (7.8)0.12%—5 dic 2023
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
CVE-2023-28550Alta (7.8)0.12%—5 dic 2023
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
CVE-2023-28546Alta (7.8)0.11%—5 dic 2023
Memory Corruption in SPS Application while exporting public key in sorter TA.
CVE-2023-28556Alta (7.8)0.12%—7 nov 2023
Cryptographic issue in HLOS during key management.
CVE-2023-24852Alta (7.8)0.12%—7 nov 2023
Memory Corruption in Core due to secure memory access by user while loading modem image.
CVE-2023-22388Crítica (9.8)0.35%—7 nov 2023
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
CVE-2023-22385Crítica (9.8)0.35%—3 oct 2023
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
CVE-2023-28565Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
CVE-2023-21625Alta (7.5)0.35%—8 ago 2023
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation3
  2. T1059 Command and Scripting Interpreter2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm