« Volver al listado

Qualcomm

Qualcomm Snapdragon 8 GEN 1 Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon 8 GEN 1 Firmware tiene 48 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE48
Últimos 12 meses9
Críticas2
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47373Alta (7.8)0.07%—2 mar 2026
Memory Corruption when accessing buffers with invalid length during TA invocation.
CVE-2025-47371Media (6.5)0.11%—2 mar 2026
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
CVE-2025-47348Alta (7.8)0.08%—7 ene 2026
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47333Media (6.6)0.08%—7 ene 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47331Media (6.1)0.08%—7 ene 2026
Information disclosure while processing a firmware event.
CVE-2025-47330Media (5.5)0.07%—7 ene 2026
Transient DOS while parsing video packets received from the video firmware.
CVE-2025-47323Alta (7.8)0.09%—18 dic 2025
Memory corruption while routing GPR packets between user and root when handling large data packet.
CVE-2025-21424Alta (7.8)0.12%—3 mar 2025
Memory corruption while calling the NPU driver APIs concurrently.
CVE-2024-53027Alta (7.5)0.30%—3 mar 2025
Transient DOS may occur while processing the country IE.
CVE-2024-53024Alta (7.8)0.12%—3 mar 2025
Memory corruption in display driver while detaching a device.
CVE-2024-53014Alta (7.8)0.12%—3 mar 2025
Memory corruption may occur while validating ports and channels in Audio driver.
CVE-2024-43062Alta (7.8)0.12%—3 mar 2025
Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.
CVE-2024-43059Alta (7.8)0.12%—3 mar 2025
Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
CVE-2024-43057Alta (7.8)0.12%—3 mar 2025
Memory corruption while processing command in Glink linux.
CVE-2024-43056Media (6.5)0.11%—3 mar 2025
Transient DOS during hypervisor virtual I/O operation in a virtual machine.
CVE-2024-43055Alta (7.8)0.13%—3 mar 2025
Memory corruption while processing camera use case IOCTL call.
CVE-2024-43051Media (5.5)0.11%—3 mar 2025
Information disclosure while deriving keys for a session for any Widevine use case.
CVE-2024-38426Media (5.3)0.27%—3 mar 2025
While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-33051Alta (7.5)0.30%—2 sept 2024
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
CVE-2024-33050Alta (7.5)0.30%—2 sept 2024
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
CVE-2024-33045Alta (7.8)0.12%—2 sept 2024
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
CVE-2024-33042Alta (7.8)0.13%—2 sept 2024
Memory corruption when Alternative Frequency offset value is set to 255.
CVE-2024-33038Alta (7.8)0.10%—2 sept 2024
Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.
CVE-2023-33021Alta (7.8)0.12%—5 sept 2023
Memory corruption in Graphics while processing user packets for command submission.
CVE-2023-33016Alta (7.5)0.38%—5 sept 2023
Transient DOS in WLAN firmware while parsing MLO (multi-link operation).
CVE-2023-33015Alta (7.5)0.38%—5 sept 2023
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
CVE-2023-28584Alta (7.5)0.35%—5 sept 2023
Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).
CVE-2023-28581Crítica (9.8)0.50%—5 sept 2023
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter11
  2. T1068 Exploitation for Privilege Escalation11
  3. T1041 Exfiltration Over C2 Channel1
  4. T1190 Exploit Public-Facing Application1
  5. T1210 Exploitation of Remote Services1
  6. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm