« Volver al listado

Qualcomm

Qualcomm Snapdragon AR2 GEN 1 Platform Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon AR2 GEN 1 Platform Firmware tiene 161 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 5 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE161
Últimos 12 meses16
Críticas5
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33063Alta (7.8)0.67%⚠ Explotación activa5 dic 2023
Memory corruption in DSP Services during a remote call from HLOS to DSP.
CVE-2023-33106Alta (7.8)0.79%⚠ Explotación activa5 dic 2023
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
CVE-2023-33107Alta (7.8)0.74%⚠ Explotación activa5 dic 2023
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-47369Media (5.5)0.08%—7 ene 2026
Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.
CVE-2025-47348Alta (7.8)0.08%—7 ene 2026
Memory corruption while processing identity credential operations in the trusted application.
CVE-2025-47344Media (6.4)0.06%—7 ene 2026
Memory corruption while handling sensor utility operations.
CVE-2025-47334Media (6.7)0.08%—7 ene 2026
Memory corruption while processing shared command buffer packet between camera userspace and kernel.
CVE-2025-47333Media (6.6)0.08%—7 ene 2026
Memory corruption while handling buffer mapping operations in the cryptographic driver.
CVE-2025-47332Media (6.4)0.06%—7 ene 2026
Memory corruption while processing a config call from userspace.
CVE-2025-47331Media (6.1)0.08%—7 ene 2026
Information disclosure while processing a firmware event.
CVE-2025-47330Media (5.5)0.07%—7 ene 2026
Transient DOS while parsing video packets received from the video firmware.
CVE-2025-47321Alta (7.8)0.08%—18 dic 2025
Memory corruption while copying packets received from unix clients.
CVE-2025-47319Media (6.7)0.09%—18 dic 2025
Information disclosure while exposing internal TA-to-TA communication APIs to HLOS
CVE-2025-27063Alta (7.8)0.10%—18 dic 2025
Memory corruption during video playback when video session open fails with time out error.
CVE-2025-47323Alta (7.8)0.09%—18 dic 2025
Memory corruption while routing GPR packets between user and root when handling large data packet.
CVE-2025-47370Media (6.5)0.12%—4 nov 2025
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
CVE-2025-27070Alta (7.8)0.06%—4 nov 2025
Memory corruption while performing encryption and decryption commands.
CVE-2025-27054Alta (7.8)0.09%—9 oct 2025
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-47318Alta (7.5)0.21%—24 sept 2025
Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-27032Alta (7.8)0.08%—24 sept 2025
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-27073Alta (7.5)0.21%—6 ago 2025
Transient DOS while creating NDP instance.
CVE-2025-27066Alta (7.5)0.28%—6 ago 2025
Transient DOS while processing an ANQP message.
CVE-2025-27065Alta (7.5)0.21%—6 ago 2025
Transient DOS while processing a frame with malformed shared-key descriptor.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-21463Alta (7.5)0.23%—3 jun 2025
Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2024-53010Alta (7.8)0.08%—3 jun 2025
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
CVE-2025-21448Alta (7.5)0.26%—7 abr 2025
Transient DOS may occur while parsing SSID in action frames.
CVE-2025-21434Alta (7.5)0.26%—7 abr 2025
Transient DOS may occur while parsing EHT operation IE or EHT capability IE.
CVE-2025-21430Alta (7.5)0.26%—7 abr 2025
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
CVE-2024-49848Media (6.7)0.14%—7 abr 2025
Memory corruption while processing multiple IOCTL calls from HLOS to DSP.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation20
  2. T1059 Command and Scripting Interpreter15
  3. T1190 Exploit Public-Facing Application12
  4. T1499.004 Application or System Exploitation8
  5. T1005 Data from Local System3
  6. T1499 Endpoint Denial of Service2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm