« Volver al listado

Qualcomm

Qualcomm Sd820 Firmware: vulnerabilidades y CVE

Qualcomm Sd820 Firmware tiene 160 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 36 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE160
Últimos 12 meses2
Críticas36
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2020-11261Alta (7.8)1.6%⚠ Explotación activa9 jun 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-27074Alta (7.8)0.08%—4 nov 2025
Memory corruption while processing a GP command response.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-21454Alta (7.5)0.22%—8 jul 2025
Transient DOS while processing received beacon frame.
CVE-2025-21449Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2018-11816Alta (7.8)0.11%—26 nov 2024
Crafted Binder Request Causes Heap UAF in MediaServer
CVE-2016-10408Alta (7.8)0.10%—26 nov 2024
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-21461Alta (7.8)0.10%—1 jul 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2023-43551Alta (7.5)0.26%—3 jun 2024
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2024-21468Alta (7.8)0.11%—1 abr 2024
Memory corruption when there is failed unmap operation in GPU.
CVE-2023-33023Alta (7.8)0.11%—1 abr 2024
Memory corruption while processing finish_sign command to pass a rsp buffer.
CVE-2023-28547Alta (7.8)0.11%—1 abr 2024
Memory corruption in SPS Application while requesting for public key in sorter TA.
CVE-2023-33066Alta (7.8)0.11%—4 mar 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-43511Alta (7.5)0.32%—2 ene 2024
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33033Alta (7.8)0.12%—2 ene 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33030Alta (7.8)0.12%—2 ene 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-28586Media (6.5)0.14%—5 dic 2023
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
CVE-2023-28551Alta (7.8)0.12%—5 dic 2023
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
CVE-2023-28550Alta (7.8)0.12%—5 dic 2023
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
CVE-2023-28546Alta (7.8)0.11%—5 dic 2023
Memory Corruption in SPS Application while exporting public key in sorter TA.
CVE-2023-33059Alta (7.8)0.11%—7 nov 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-28563Media (5.5)0.14%—7 nov 2023
Information disclosure in IOE Firmware while handling WMI command.
CVE-2023-22388Crítica (9.8)0.35%—7 nov 2023
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
CVE-2023-24849Alta (7.5)0.30%—3 oct 2023
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
CVE-2023-24848Alta (7.5)0.30%—3 oct 2023
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
CVE-2023-22385Crítica (9.8)0.35%—3 oct 2023
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
CVE-2023-28565Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation6
  2. T1059 Command and Scripting Interpreter4
  3. T1499.004 Application or System Exploitation3
  4. T1190 Exploit Public-Facing Application2
  5. T1552.001 Credentials In Files1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm