« Volver al listado

Qualcomm

Qualcomm Sm7250-aa Firmware: vulnerabilidades y CVE

Qualcomm Sm7250-aa Firmware tiene 62 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE62
Últimos 12 meses0
Críticas2
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33063Alta (7.8)0.58%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-23373Alta (7.8)0.15%—1 jul 2024
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
CVE-2024-23368Alta (7.8)0.10%—1 jul 2024
Memory corruption when allocating and accessing an entry in an SMEM partition.
CVE-2024-21469Alta (7.8)0.10%—1 jul 2024
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
CVE-2024-21465Alta (7.8)0.10%—1 jul 2024
Memory corruption while processing key blob passed by the user.
CVE-2024-21462Media (5.5)0.09%—1 jul 2024
Transient DOS while loading the TA ELF file.
CVE-2024-21461Alta (7.8)0.10%—1 jul 2024
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33079Alta (7.8)0.16%—5 dic 2023
Memory corruption in Audio while running invalid audio recording from ADSP.
CVE-2023-33063Alta (7.8)0.58%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33054Crítica (9.1)0.36%—5 dic 2023
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
CVE-2023-33044Alta (7.5)0.52%—5 dic 2023
Transient DOS in Data modem while handling TLB control messages from the Network.
CVE-2023-33042Alta (7.5)0.61%—5 dic 2023
Transient DOS in Modem after RRC Setup message is received.
CVE-2023-33022Alta (7.8)0.16%—5 dic 2023
Memory corruption in HLOS while invoking IOCTL calls from user-space.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
CVE-2023-33059Alta (7.8)0.11%—7 nov 2023
Memory corruption in Audio while processing the VOC packet data from ADSP.
CVE-2023-33055Alta (7.8)0.14%—7 nov 2023
Memory Corruption in Audio while invoking callback function in driver from ADSP.
CVE-2023-33031Alta (7.8)0.11%—7 nov 2023
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.
CVE-2023-33035Alta (7.8)0.12%—3 oct 2023
Memory corruption while invoking callback function of AFE from ADSP.
CVE-2023-33027Alta (7.5)0.39%—3 oct 2023
Transient DOS in WLAN Firmware while parsing rsn ies.
CVE-2023-28540Alta (7.5)0.43%—3 oct 2023
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
CVE-2023-24853Alta (7.8)0.12%—3 oct 2023
Memory Corruption in HLOS while registering for key provisioning notify.
CVE-2023-24850Alta (7.8)0.12%—3 oct 2023
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
CVE-2023-24849Alta (7.5)0.36%—3 oct 2023
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
CVE-2023-24848Alta (7.5)0.36%—3 oct 2023
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
CVE-2023-24847Alta (7.5)0.39%—3 oct 2023
Transient DOS in Modem while allocating DSM items.
CVE-2023-24843Alta (7.5)0.38%—3 oct 2023
Transient DOS in Modem while triggering a camping on an 5G cell.
CVE-2023-22385Crítica (9.8)0.42%—3 oct 2023
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
CVE-2023-21673Alta (7.8)0.10%—3 oct 2023
Improper Access to the VM resource manager can lead to Memory Corruption.
CVE-2023-28560Alta (7.8)0.12%—5 sept 2023
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm