Qualcomm
Qualcomm Snapdragon X20 LTE Modem Firmware: vulnerabilidades y CVE
Qualcomm Snapdragon X20 LTE Modem Firmware tiene 34 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE34
Últimos 12 meses0
Críticas2
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-33107 | Alta (7.8) | 0.74% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-21482 | Alta (7.1) | 0.08% | — | 24 sept 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2025-21454 | Alta (7.5) | 0.22% | — | 8 jul 2025 | Transient DOS while processing received beacon frame. |
| CVE-2025-21449 | Alta (7.5) | 0.22% | — | 8 jul 2025 | Transient DOS may occur while processing malformed length field in SSID IEs. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-38423 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing GPU page table switch. |
| CVE-2024-38422 | Alta (7.8) | 0.10% | — | 4 nov 2024 | Memory corruption while processing voice packet with arbitrary data received from ADSP. |
| CVE-2024-33016 | Media (6.8) | 0.15% | — | 2 sept 2024 | memory corruption when an invalid firehose patch command is invoked. |
| CVE-2024-21471 | Alta (7.8) | 0.11% | — | 6 may 2024 | Memory corruption when IOMMU unmap of a GPU buffer fails in Linux. |
| CVE-2024-21468 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption when there is failed unmap operation in GPU. |
| CVE-2023-33066 | Alta (7.8) | 0.11% | — | 4 mar 2024 | Memory corruption in Audio while processing RT proxy port register driver. |
| CVE-2023-43511 | Alta (7.5) | 0.32% | — | 2 ene 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| CVE-2023-33120 | Alta (7.8) | 0.11% | — | 2 ene 2024 | Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
| CVE-2023-33033 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in Audio during playback with speaker protection. |
| CVE-2023-33107 | Alta (7.8) | 0.74% | ⚠ Explotación activa | 5 dic 2023 | Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
| CVE-2023-33080 | Alta (7.5) | 0.34% | — | 5 dic 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| CVE-2023-33018 | Alta (7.8) | 0.11% | — | 5 dic 2023 | Memory corruption while using the UIM diag command to get the operators name. |
| CVE-2023-28551 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. |
| CVE-2023-28550 | Alta (7.8) | 0.12% | — | 5 dic 2023 | Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
| CVE-2023-33059 | Alta (7.8) | 0.11% | — | 7 nov 2023 | Memory corruption in Audio while processing the VOC packet data from ADSP. |
| CVE-2023-22388 | Crítica (9.8) | 0.35% | — | 7 nov 2023 | Memory Corruption in Multi-mode Call Processor while processing bit mask API. |
| CVE-2023-24849 | Alta (7.5) | 0.36% | — | 3 oct 2023 | Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| CVE-2023-24848 | Alta (7.5) | 0.36% | — | 3 oct 2023 | Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| CVE-2023-24847 | Alta (7.5) | 0.39% | — | 3 oct 2023 | Transient DOS in Modem while allocating DSM items. |
| CVE-2023-22385 | Crítica (9.8) | 0.42% | — | 3 oct 2023 | Memory Corruption in Data Modem while making a MO call or MT VOLTE call. |
| CVE-2023-21628 | Alta (7.8) | 0.12% | — | 6 jun 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. |
| CVE-2022-40521 | Alta (7.5) | 0.35% | — | 6 jun 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-33264 | Alta (7.8) | 0.11% | — | 6 jun 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2022-40504 | Alta (7.5) | 0.38% | — | 2 may 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. |
| CVE-2023-21666 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. |
| CVE-2023-21665 | Alta (7.8) | 0.18% | — | 2 may 2023 | Memory corruption in Graphics while importing a file. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.