« Back to list

Qualcomm

Qualcomm Sc8180xp-acaf Firmware: vulnerabilities and CVEs

Qualcomm Sc8180xp-acaf Firmware has 33 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs33
Last 12 months1
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-47359High (7.8)0.10%—Feb 2, 2026
Memory Corruption when multiple threads simultaneously access a memory free API.
CVE-2025-27055High (7.8)0.09%—Jul 8, 2025
Memory corruption during the image encoding process.
CVE-2025-27050High (7.8)0.09%—Jul 8, 2025
Memory corruption while processing event close when client process terminates abruptly.
CVE-2025-27046High (7.8)0.09%—Jul 8, 2025
Memory corruption while processing multiple simultaneous escape calls.
CVE-2025-21466High (7.8)0.09%—Jul 8, 2025
Memory corruption while processing a private escape command in an event trigger.
CVE-2025-21454High (7.5)0.22%—Jul 8, 2025
Transient DOS while processing received beacon frame.
CVE-2025-21449High (7.5)0.22%—Jul 8, 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2025-21422High (7.8)0.10%—Jul 8, 2025
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
CVE-2024-53009High (7.8)0.09%—Jul 8, 2025
Memory corruption while operating the mailbox in Automotive.
CVE-2025-21475High (7.8)0.11%—May 6, 2025
Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
CVE-2024-49842High (7.8)0.09%—May 6, 2025
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
CVE-2024-49841High (7.8)0.11%—May 6, 2025
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
CVE-2024-43056Medium (6.5)0.11%—Mar 3, 2025
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
CVE-2024-38420High (7.8)0.10%—Feb 3, 2025
Memory corruption while configuring a Hypervisor based input virtual device.
CVE-2024-45542High (7.8)0.13%—Jan 6, 2025
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
CVE-2024-45541High (7.8)0.11%—Jan 6, 2025
Memory corruption when IOCTL call is invoked from user-space to read board data.
CVE-2023-43551High (7.5)0.26%—Jun 3, 2024
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2023-43542High (7.8)0.10%—Jun 3, 2024
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
CVE-2023-43538High (7.8)0.10%—Jun 3, 2024
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
CVE-2024-21477High (7.5)0.32%—May 6, 2024
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
CVE-2024-21476High (7.8)0.13%—May 6, 2024
Memory corruption when the channel ID passed by user is not validated and further used.
CVE-2023-43530High (7.8)0.11%—May 6, 2024
Memory corruption in HLOS while checking for the storage type.
CVE-2023-43529High (7.5)0.32%—May 6, 2024
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
CVE-2023-33119High (7)0.08%—May 6, 2024
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
CVE-2024-21470High (7.8)0.11%—Apr 1, 2024
Memory corruption while allocating memory for graphics.
CVE-2023-33115High (7.8)0.11%—Apr 1, 2024
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
CVE-2023-33023High (7.8)0.11%—Apr 1, 2024
Memory corruption while processing finish_sign command to pass a rsp buffer.
CVE-2023-28547High (7.8)0.11%—Apr 1, 2024
Memory corruption in SPS Application while requesting for public key in sorter TA.
CVE-2023-43541High (7.8)0.11%—Mar 4, 2024
Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.
CVE-2023-33086High (7.5)0.32%—Mar 4, 2024
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation13
  2. T1059 Command and Scripting Interpreter11
  3. T1190 Exploit Public-Facing Application2
  4. T1499.004 Application or System Exploitation2
  5. T1005 Data from Local System1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm