« Volver al listado

Qualcomm

Qualcomm Smart Audio 200 Platform Firmware: vulnerabilidades y CVE

Qualcomm Smart Audio 200 Platform Firmware tiene 37 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE37
Últimos 12 meses0
Críticas2
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33107Alta (7.8)0.89%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-21484Alta (8.2)0.26%—24 sept 2025
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
CVE-2025-21449Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2025-21429Alta (7.5)0.26%—7 abr 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
CVE-2025-21428Alta (7.5)0.25%—7 abr 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
CVE-2024-45552Alta (8.2)0.26%—7 abr 2025
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
CVE-2024-43052Alta (7.8)0.10%—2 dic 2024
Memory corruption while processing API calls to NPU with invalid input.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-38423Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing GPU page table switch.
CVE-2024-38422Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-23385Media (6.5)0.25%—4 nov 2024
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
CVE-2024-33043Media (5.5)0.09%—2 sept 2024
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
CVE-2024-23359Alta (8.2)0.26%—2 sept 2024
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-23358Alta (7.5)0.26%—2 sept 2024
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2023-33069Alta (7.8)0.11%—6 feb 2024
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
CVE-2023-33068Alta (7.8)0.11%—6 feb 2024
Memory corruption in Audio while processing IIR config data from AFE calibration block.
CVE-2023-33067Alta (7.8)0.11%—6 feb 2024
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
CVE-2023-43511Alta (7.5)0.32%—2 ene 2024
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33120Alta (7.8)0.11%—2 ene 2024
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
CVE-2023-33033Alta (7.8)0.12%—2 ene 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33030Alta (7.8)0.12%—2 ene 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33107Alta (7.8)0.89%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
CVE-2023-28588Alta (7.5)0.52%—5 dic 2023
Transient DOS in Bluetooth Host while rfc slot allocation.
CVE-2023-28586Media (6.5)0.14%—5 dic 2023
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
CVE-2023-28551Alta (7.8)0.12%—5 dic 2023
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.
CVE-2023-28550Alta (7.8)0.12%—5 dic 2023
Memory corruption in MPP performance while accessing DSM watermark using external memory address.
CVE-2023-22388Crítica (9.8)0.35%—7 nov 2023
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
CVE-2023-24849Alta (7.5)0.30%—3 oct 2023
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
CVE-2023-24848Alta (7.5)0.30%—3 oct 2023
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
CVE-2023-22385Crítica (9.8)0.35%—3 oct 2023
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation5
  2. T1190 Exploit Public-Facing Application5
  3. T1059 Command and Scripting Interpreter4
  4. T1499.004 Application or System Exploitation3
  5. T1005 Data from Local System2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm