« Volver al listado

Qualcomm

Qualcomm Sm6250p Firmware: vulnerabilidades y CVE

Qualcomm Sm6250p Firmware tiene 353 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 60 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE353
Últimos 12 meses1
Críticas60
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2020-11261Alta (7.8)1.6%⚠ Explotación activa9 jun 2021
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,…
CVE-2021-1906Media (5.5)0.52%⚠ Explotación activa7 may 2021
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
CVE-2021-1905Alta (7.8)1.5%⚠ Explotación activa7 may 2021
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-21481Alta (7.8)0.07%—24 sept 2025
Memory corruption while performing private key encryption in trusted application.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-21454Alta (7.5)0.22%—8 jul 2025
Transient DOS while processing received beacon frame.
CVE-2025-21449Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-33044Alta (7.8)0.10%—2 dic 2024
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
CVE-2024-38408Crítica (9.1)0.14%—4 nov 2024
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
CVE-2024-33051Alta (7.5)0.30%—2 sept 2024
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-33016Media (6.8)0.15%—2 sept 2024
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-21465Alta (7.8)0.10%—1 jul 2024
Memory corruption while processing key blob passed by the user.
CVE-2024-21462Media (5.5)0.09%—1 jul 2024
Transient DOS while loading the TA ELF file.
CVE-2024-21461Alta (7.8)0.10%—1 jul 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2023-43551Alta (7.5)0.26%—3 jun 2024
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2024-21477Alta (7.5)0.32%—6 may 2024
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
CVE-2023-43529Alta (7.5)0.32%—6 may 2024
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
CVE-2023-33023Alta (7.8)0.11%—1 abr 2024
Memory corruption while processing finish_sign command to pass a rsp buffer.
CVE-2023-28547Alta (7.8)0.11%—1 abr 2024
Memory corruption in SPS Application while requesting for public key in sorter TA.
CVE-2023-33086Alta (7.5)0.32%—4 mar 2024
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
CVE-2023-33066Alta (7.8)0.11%—4 mar 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-28578Alta (7.8)0.12%—4 mar 2024
Memory corruption in Core Services while executing the command for removing a single event listener.
CVE-2023-43536Alta (7.5)0.32%—6 feb 2024
Transient DOS while parse fils IE with length equal to 1.
CVE-2023-43533Alta (7.5)0.32%—6 feb 2024
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
CVE-2023-43522Alta (7.5)0.32%—6 feb 2024
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
CVE-2023-43511Alta (7.5)0.32%—2 ene 2024
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33109Alta (7.5)0.34%—2 ene 2024
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation8
  2. T1059 Command and Scripting Interpreter5
  3. T1190 Exploit Public-Facing Application4
  4. T1499.004 Application or System Exploitation3
  5. T1040 Network Sniffing1
  6. T1499 Endpoint Denial of Service1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm