« Back to list

Qualcomm

Qualcomm Sdx55m Firmware: vulnerabilities and CVEs

Qualcomm Sdx55m Firmware has 452 published vulnerabilities, 0 of them in the last 12 months. 73 are rated critical and 4 are listed by CISA as actively exploited.

CVEs452
Last 12 months0
Critical73
Actively exploited4

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-22071High (7.8)0.46%⚠ Active exploitationJun 14, 2022
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2020-11261High (7.8)1.6%⚠ Active exploitationJun 9, 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2021-1906Medium (5.5)0.52%⚠ Active exploitationMay 7, 2021
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1905High (7.8)1.5%⚠ Active exploitationMay 7, 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-30299Medium (6.7)0.12%—Nov 22, 2024
Possible out of bound access in audio module due to lack of validation of user provided input.
CVE-2023-21667Medium (6.5)0.37%—Sep 5, 2023
Transient DOS in Bluetooth HOST while passing descriptor to validate the blacklisted BT keyboard.
CVE-2023-21664High (7.8)0.12%—Sep 5, 2023
Memory Corruption in Core Platform while printing the response buffer in log.
CVE-2023-21662High (7.8)0.12%—Sep 5, 2023
Memory corruption in Core Platform while printing the response buffer in log.
CVE-2023-21654High (7.8)0.11%—Sep 5, 2023
Memory corruption in Audio during playback session with audio effects enabled.
CVE-2023-21646High (7.5)0.38%—Sep 5, 2023
Transient DOS in Modem while processing invalid System Information Block 1.
CVE-2023-21644High (7.8)0.11%—Sep 5, 2023
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
CVE-2023-21636High (7.8)0.11%—Sep 5, 2023
Memory Corruption due to improper validation of array index in Linux while updating adn record.
CVE-2022-40524High (7.8)0.11%—Sep 5, 2023
Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
CVE-2022-33220Medium (5.5)0.11%—Sep 5, 2023
Information disclosure in Automotive multimedia due to buffer over-read.
CVE-2023-22666High (7.8)0.12%—Aug 8, 2023
Memory Corruption in Audio while playing amrwbplus clips with modified content.
CVE-2023-21652High (7.1)0.10%—Aug 8, 2023
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
CVE-2023-21651High (7.8)0.12%—Aug 8, 2023
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
CVE-2023-21650High (7.8)0.11%—Aug 8, 2023
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
CVE-2023-21649High (7.8)0.11%—Aug 8, 2023
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
CVE-2023-21647Medium (6.5)0.39%—Aug 8, 2023
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
CVE-2023-21627High (7.8)0.12%—Aug 8, 2023
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
CVE-2023-21626High (7.1)0.11%—Aug 8, 2023
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
CVE-2022-40510Critical (9.8)0.43%—Aug 8, 2023
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
CVE-2022-40537Critical (9.8)0.36%—Mar 10, 2023
Memory corruption in Bluetooth HOST while processing the AVRC_PDU_GET_PLAYER_APP_VALUE_TEXT AVRCP response.
CVE-2022-40535High (7.5)0.41%—Mar 10, 2023
Transient DOS due to buffer over-read in WLAN while sending a packet to device.
CVE-2022-40531High (7.8)0.12%—Mar 10, 2023
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
CVE-2022-40530High (7.8)0.13%—Mar 10, 2023
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
CVE-2022-40515Critical (9.8)0.33%—Mar 10, 2023
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
CVE-2022-33278High (7.8)0.12%—Mar 10, 2023
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
CVE-2022-33272High (7.5)0.41%—Mar 10, 2023
Transient DOS in modem due to reachable assertion.
CVE-2022-33257High (7)0.09%—Mar 10, 2023
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
CVE-2022-33256Critical (9.8)0.53%—Mar 10, 2023
Memory corruption due to improper validation of array index in Multi-mode call processor.
CVE-2022-33254High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
CVE-2022-33250High (7.5)0.41%—Mar 10, 2023
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation4
  2. T1059 Command and Scripting Interpreter3
  3. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Qualcomm