Qualcomm
Qualcomm Sm7250-aa Firmware: vulnerabilidades y CVE
Qualcomm Sm7250-aa Firmware tiene 62 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE62
Últimos 12 meses0
Críticas2
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33063 | Alta (7.8) | 0.58% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-23373 | Alta (7.8) | 0.15% | — | 1 jul 2024 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. |
| CVE-2024-23368 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition. |
| CVE-2024-21469 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption when an invoke call and a TEE call are bound for the same trusted application. |
| CVE-2024-21465 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while processing key blob passed by the user. |
| CVE-2024-21462 | Media (5.5) | 0.09% | — | 1 jul 2024 | Transient DOS while loading the TA ELF file. |
| CVE-2024-21461 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
| CVE-2023-33080 | Alta (7.5) | 0.34% | — | 5 dic 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| CVE-2023-33079 | Alta (7.8) | 0.16% | — | 5 dic 2023 | Memory corruption in Audio while running invalid audio recording from ADSP. |
| CVE-2023-33063 | Alta (7.8) | 0.58% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in DSP Services during a remote call from HLOS to DSP. |
| CVE-2023-33054 | Crítica (9.1) | 0.36% | — | 5 dic 2023 | Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. |
| CVE-2023-33044 | Alta (7.5) | 0.52% | — | 5 dic 2023 | Transient DOS in Data modem while handling TLB control messages from the Network. |
| CVE-2023-33042 | Alta (7.5) | 0.61% | — | 5 dic 2023 | Transient DOS in Modem after RRC Setup message is received. |
| CVE-2023-33022 | Alta (7.8) | 0.16% | — | 5 dic 2023 | Memory corruption in HLOS while invoking IOCTL calls from user-space. |
| CVE-2023-33018 | Alta (7.8) | 0.11% | — | 5 dic 2023 | Memory corruption while using the UIM diag command to get the operators name. |
| CVE-2023-33017 | Alta (7.8) | 0.16% | — | 5 dic 2023 | Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. |
| CVE-2023-33059 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-33055 | Alta (7.8) | 0.14% | — | 7 nov 2023 | Memory Corruption in Audio while invoking callback function in driver from ADSP. |
| CVE-2023-33031 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. |
| CVE-2023-33035 | Alta (7.8) | 0.12% | — | 3 oct 2023 | Memory corruption while invoking callback function of AFE from ADSP. |
| CVE-2023-33027 | Alta (7.5) | 0.39% | — | 3 oct 2023 | Transient DOS in WLAN Firmware while parsing rsn ies. |
| CVE-2023-28540 | Alta (7.5) | 0.43% | — | 3 oct 2023 | Cryptographic issue in Data Modem due to improper authentication during TLS handshake. |
| CVE-2023-24853 | Alta (7.8) | 0.12% | — | 3 oct 2023 | Memory Corruption in HLOS while registering for key provisioning notify. |
| CVE-2023-24850 | Alta (7.8) | 0.12% | — | 3 oct 2023 | Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. |
| CVE-2023-24849 | Alta (7.5) | 0.36% | — | 3 oct 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| CVE-2023-24848 | Alta (7.5) | 0.36% | — | 3 oct 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| CVE-2023-24847 | Alta (7.5) | 0.39% | — | 3 oct 2023 | Transient DOS in Modem while allocating DSM items. |
| CVE-2023-24843 | Alta (7.5) | 0.38% | — | 3 oct 2023 | Transient DOS in Modem while triggering a camping on an 5G cell. |
| CVE-2023-22385 | Crítica (9.8) | 0.42% | — | 3 oct 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. |
| CVE-2023-21673 | Alta (7.8) | 0.10% | — | 3 oct 2023 | Improper Access to the VM resource manager can lead to Memory Corruption. |
| CVE-2023-28560 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.