Qualcomm
Qualcomm Snapdragon 430 Mobile Platform Firmware: vulnerabilidades y CVE
Qualcomm Snapdragon 430 Mobile Platform Firmware tiene 24 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27053 | Alta (7.8) | 0.09% | — | 9 oct 2025 | Memory corruption during PlayReady APP usecase while processing TA commands. |
| CVE-2025-21482 | Alta (7.1) | 0.08% | — | 24 sept 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2024-43052 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption while processing API calls to NPU with invalid input. |
| CVE-2024-23385 | Media (6.5) | 0.25% | — | 4 nov 2024 | Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. |
| CVE-2024-23359 | Alta (8.2) | 0.26% | — | 2 sept 2024 | Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. |
| CVE-2024-23358 | Alta (7.5) | 0.26% | — | 2 sept 2024 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem. |
| CVE-2024-23357 | Media (5.5) | 0.09% | — | 5 ago 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. |
| CVE-2024-23353 | Alta (7.5) | 0.35% | — | 5 ago 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
| CVE-2024-21461 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
| CVE-2023-33110 | Alta (7) | 0.08% | — | 2 ene 2024 | The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close… |
| CVE-2023-33033 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in Audio during playback with speaker protection. |
| CVE-2023-33030 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in HLOS while running playready use-case. |
| CVE-2023-33018 | Alta (7.8) | 0.11% | — | 5 dic 2023 | Memory corruption while using the UIM diag command to get the operators name. |
| CVE-2023-28551 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. |
| CVE-2023-28550 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
| CVE-2023-28546 | Alta (7.8) | 0.11% | — | 5 dic 2023 | Memory Corruption in SPS Application while exporting public key in sorter TA. |
| CVE-2023-22388 | Crítica (9.8) | 0.35% | — | 7 nov 2023 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. |
| CVE-2023-24850 | Alta (7.8) | 0.12% | — | 3 oct 2023 | Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. |
| CVE-2023-24849 | Alta (7.5) | 0.36% | — | 3 oct 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| CVE-2023-24848 | Alta (7.5) | 0.36% | — | 3 oct 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| CVE-2023-22385 | Crítica (9.8) | 0.42% | — | 3 oct 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. |
| CVE-2022-40521 | Alta (7.5) | 0.35% | — | 6 jun 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-33264 | Alta (7.8) | 0.11% | — | 6 jun 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2022-22076 | Media (5.5) | 0.11% | — | 6 jun 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.