« Volver al listado

Qualcomm

Qualcomm Snapdragon X5 LTE Modem Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon X5 LTE Modem Firmware tiene 70 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 6 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE70
Últimos 12 meses5
Críticas6
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-24088Alta (8.2)0.07%—1 jun 2026
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
CVE-2026-21385Alta (7.8)1.3%⚠ Explotación activa2 mar 2026
Memory corruption while using alignments for memory allocation.
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47320Alta (7.8)0.08%—18 dic 2025
Memory corruption while processing MFC channel configuration during music playback.
CVE-2025-27053Alta (7.8)0.09%—9 oct 2025
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-47318Alta (7.5)0.21%—24 sept 2025
Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-21454Alta (7.5)0.22%—8 jul 2025
Transient DOS while processing received beacon frame.
CVE-2025-21449Alta (7.5)0.22%—8 jul 2025
Transient DOS may occur while processing malformed length field in SSID IEs.
CVE-2025-21430Alta (7.5)0.26%—7 abr 2025
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
CVE-2025-21429Alta (7.5)0.26%—7 abr 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
CVE-2025-21428Alta (7.5)0.25%—7 abr 2025
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-38423Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing GPU page table switch.
CVE-2024-38422Alta (7.8)0.10%—4 nov 2024
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2023-43551Alta (7.5)0.26%—3 jun 2024
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
CVE-2024-21468Alta (7.8)0.11%—1 abr 2024
Memory corruption when there is failed unmap operation in GPU.
CVE-2023-33066Alta (7.8)0.11%—4 mar 2024
Memory corruption in Audio while processing RT proxy port register driver.
CVE-2023-33069Alta (7.8)0.11%—6 feb 2024
Memory corruption in Audio while processing the calibration data returned from ACDB loader.
CVE-2023-33068Alta (7.8)0.11%—6 feb 2024
Memory corruption in Audio while processing IIR config data from AFE calibration block.
CVE-2023-33067Alta (7.8)0.11%—6 feb 2024
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.
CVE-2023-43511Alta (7.5)0.32%—2 ene 2024
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
CVE-2023-33120Alta (7.8)0.11%—2 ene 2024
Memory corruption in Audio when memory map command is executed consecutively in ADSP.
CVE-2023-33110Alta (7)0.08%—2 ene 2024
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close…
CVE-2023-33033Alta (7.8)0.12%—2 ene 2024
Memory corruption in Audio during playback with speaker protection.
CVE-2023-33030Alta (7.8)0.12%—2 ene 2024
Memory corruption in HLOS while running playready use-case.
CVE-2023-33080Alta (7.5)0.34%—5 dic 2023
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
CVE-2023-33018Alta (7.8)0.11%—5 dic 2023
Memory corruption while using the UIM diag command to get the operators name.
CVE-2023-33017Alta (7.8)0.16%—5 dic 2023
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation8
  2. T1190 Exploit Public-Facing Application6
  3. T1059 Command and Scripting Interpreter5
  4. T1499.004 Application or System Exploitation5
  5. T1041 Exfiltration Over C2 Channel1
  6. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm