« Volver al listado

Qualcomm

Qualcomm Snapdragon 888 5G Mobile Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 888 5G Mobile Firmware tiene 60 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE60
Últimos 12 meses2
Críticas3
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2024-43047Alta (7.8)0.67%⚠ Explotación activa7 oct 2024
Memory corruption while maintaining memory maps of HLOS memory.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-47404Alta (7.8)0.07%—4 may 2026
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
CVE-2025-47401Alta (7.5)0.22%—4 may 2026
Transient DOS when processing target power rate tables during channel configuration.
CVE-2025-27061Alta (7.8)0.09%—8 jul 2025
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVE-2025-27043Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing manipulated payload in video firmware.
CVE-2025-27042Alta (7.8)0.09%—8 jul 2025
Memory corruption while processing video packets received from video firmware.
CVE-2025-21454Alta (7.5)0.22%—8 jul 2025
Transient DOS while processing received beacon frame.
CVE-2025-21450Crítica (9.1)0.31%—8 jul 2025
Cryptographic issue occurs due to use of insecure connection method while downloading.
CVE-2025-21449Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2025-21446Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
CVE-2025-21433Media (5.5)0.08%—8 jul 2025
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
CVE-2025-21432Alta (7.8)0.09%—8 jul 2025
Memory corruption while retrieving the CBOR data from TA.
CVE-2025-21427Alta (8.2)0.22%—8 jul 2025
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
CVE-2025-21422Alta (7.8)0.10%—8 jul 2025
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
CVE-2024-53009Alta (7.8)0.09%—8 jul 2025
Memory corruption while operating the mailbox in Automotive.
CVE-2025-21468Alta (7.8)0.11%—6 may 2025
Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.
CVE-2025-21467Alta (7.8)0.11%—6 may 2025
Memory corruption while reading the FW response from the shared queue.
CVE-2025-21453Alta (7.8)0.11%—6 may 2025
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
CVE-2024-49845Alta (7.8)0.11%—6 may 2025
Memory corruption during the FRS UDS generation process.
CVE-2024-49844Alta (7.8)0.11%—6 may 2025
Memory corruption while triggering commands in the PlayReady Trusted application.
CVE-2024-49842Alta (7.8)0.09%—6 may 2025
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
CVE-2024-49841Alta (7.8)0.11%—6 may 2025
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
CVE-2024-49835Alta (7.8)0.11%—6 may 2025
Memory corruption while reading secure file.
CVE-2024-45564Alta (7.8)0.11%—6 may 2025
Memory corruption during concurrent access to server info object due to incorrect reference count update.
CVE-2024-45562Alta (7.8)0.11%—6 may 2025
Memory corruption during concurrent access to server info object due to unprotected critical field.
CVE-2024-45554Alta (7)0.11%—6 may 2025
Memory corruption during concurrent SSR execution due to race condition on the global maps list.
CVE-2024-49834Alta (7.8)0.11%—3 feb 2025
Memory corruption while power-up or power-down sequence of the camera sensor.
CVE-2024-38420Alta (7.8)0.10%—3 feb 2025
Memory corruption while configuring a Hypervisor based input virtual device.
CVE-2024-38414Media (5.5)0.10%—3 feb 2025
Information disclosure while processing information on firmware image during core initialization.
CVE-2024-43047Alta (7.8)0.67%⚠ Explotación activa7 oct 2024
Memory corruption while maintaining memory maps of HLOS memory.
CVE-2024-38402Alta (7.8)0.16%—2 sept 2024
Memory corruption while processing IOCTL call for getting group info.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation21
  2. T1059 Command and Scripting Interpreter19
  3. T1190 Exploit Public-Facing Application6
  4. T1005 Data from Local System3
  5. T1499.004 Application or System Exploitation3
  6. T1078 Valid Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm