Qualcomm
Qualcomm Snapdragon 8 GEN 1 Firmware: vulnerabilidades y CVE
Qualcomm Snapdragon 8 GEN 1 Firmware tiene 48 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE48
Últimos 12 meses9
Críticas2
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21385 | Alta (7.8) | 1.3% | ⚠ Explotación activa | 2 mar 2026 | Memory corruption while using alignments for memory allocation. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21385 | Alta (7.8) | 1.3% | ⚠ Explotación activa | 2 mar 2026 | Memory corruption while using alignments for memory allocation. |
| CVE-2025-47383 | Alta (7.2) | 0.14% | — | 2 mar 2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. |
| CVE-2025-47373 | Alta (7.8) | 0.07% | — | 2 mar 2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. |
| CVE-2025-47371 | Media (6.5) | 0.11% | — | 2 mar 2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. |
| CVE-2025-47348 | Alta (7.8) | 0.08% | — | 7 ene 2026 | Memory corruption while processing identity credential operations in the trusted application. |
| CVE-2025-47333 | Media (6.6) | 0.08% | — | 7 ene 2026 | Memory corruption while handling buffer mapping operations in the cryptographic driver. |
| CVE-2025-47331 | Media (6.1) | 0.08% | — | 7 ene 2026 | Information disclosure while processing a firmware event. |
| CVE-2025-47330 | Media (5.5) | 0.07% | — | 7 ene 2026 | Transient DOS while parsing video packets received from the video firmware. |
| CVE-2025-47323 | Alta (7.8) | 0.09% | — | 18 dic 2025 | Memory corruption while routing GPR packets between user and root when handling large data packet. |
| CVE-2025-21424 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption while calling the NPU driver APIs concurrently. |
| CVE-2024-53027 | Alta (7.5) | 0.30% | — | 3 mar 2025 | Transient DOS may occur while processing the country IE. |
| CVE-2024-53024 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption in display driver while detaching a device. |
| CVE-2024-53014 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption may occur while validating ports and channels in Audio driver. |
| CVE-2024-43062 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization. |
| CVE-2024-43059 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node. |
| CVE-2024-43057 | Alta (7.8) | 0.12% | — | 3 mar 2025 | Memory corruption while processing command in Glink linux. |
| CVE-2024-43056 | Media (6.5) | 0.11% | — | 3 mar 2025 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. |
| CVE-2024-43055 | Alta (7.8) | 0.13% | — | 3 mar 2025 | Memory corruption while processing camera use case IOCTL call. |
| CVE-2024-43051 | Media (5.5) | 0.11% | — | 3 mar 2025 | Information disclosure while deriving keys for a session for any Widevine use case. |
| CVE-2024-38426 | Media (5.3) | 0.27% | — | 3 mar 2025 | While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| CVE-2024-33051 | Alta (7.5) | 0.30% | — | 2 sept 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| CVE-2024-33050 | Alta (7.5) | 0.30% | — | 2 sept 2024 | Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
| CVE-2024-33045 | Alta (7.8) | 0.12% | — | 2 sept 2024 | Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
| CVE-2024-33042 | Alta (7.8) | 0.13% | — | 2 sept 2024 | Memory corruption when Alternative Frequency offset value is set to 255. |
| CVE-2024-33038 | Alta (7.8) | 0.10% | — | 2 sept 2024 | Memory corruption while passing untrusted/corrupted pointers from DSP to EVA. |
| CVE-2023-33021 | Alta (7.8) | 0.12% | — | 5 sept 2023 | Memory corruption in Graphics while processing user packets for command submission. |
| CVE-2023-33016 | Alta (7.5) | 0.38% | — | 5 sept 2023 | Transient DOS in WLAN firmware while parsing MLO (multi-link operation). |
| CVE-2023-33015 | Alta (7.5) | 0.38% | — | 5 sept 2023 | Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame. |
| CVE-2023-28584 | Alta (7.5) | 0.35% | — | 5 sept 2023 | Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA). |
| CVE-2023-28581 | Crítica (9.8) | 0.50% | — | 5 sept 2023 | Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.