« Volver al listado

Qualcomm

Qualcomm Snapdragon X70 Modem-rf System Firmware: vulnerabilidades y CVE

Qualcomm Snapdragon X70 Modem-rf System Firmware tiene 74 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE74
Últimos 12 meses4
Críticas6
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-24084Alta (7.5)0.25%—4 ago 2026
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVE-2025-47392Alta (8.8)0.17%—6 abr 2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
CVE-2025-47383Alta (7.2)0.14%—2 mar 2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
CVE-2025-47323Alta (7.8)0.09%—18 dic 2025
Memory corruption while routing GPR packets between user and root when handling large data packet.
CVE-2025-27034Crítica (9.8)0.40%—24 sept 2025
Memory corruption while selecting the PLMN from SOR failed list.
CVE-2025-21482Alta (7.1)0.08%—24 sept 2025
Cryptographic issue while performing RSA PKCS padding decoding.
CVE-2025-21477Alta (7.5)0.21%—6 ago 2025
Transient DOS while processing CCCH data when NW sends data with invalid length.
CVE-2025-21465Media (6.5)0.09%—6 ago 2025
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464Media (6.5)0.09%—6 ago 2025
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2024-45549Alta (7.7)0.12%—7 abr 2025
Information disclosure while creating MQ channels.
CVE-2024-43046Media (5.5)0.11%—7 abr 2025
There may be information disclosure during memory re-allocation in TZ Secure OS.
CVE-2024-33056Alta (7.8)0.10%—2 dic 2024
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
CVE-2024-23385Media (6.5)0.25%—4 nov 2024
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
CVE-2024-33016Media (6.8)0.15%—2 sept 2024
memory corruption when an invalid firehose patch command is invoked.
CVE-2024-23362Alta (7.1)0.12%—2 sept 2024
Cryptographic issue while parsing RSA keys in COBR format.
CVE-2024-23359Alta (8.2)0.26%—2 sept 2024
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
CVE-2024-23353Alta (7.5)0.35%—5 ago 2024
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2024-23352Alta (7.5)0.35%—5 ago 2024
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
CVE-2024-21469Alta (7.8)0.10%—1 jul 2024
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
CVE-2024-21465Alta (7.8)0.10%—1 jul 2024
Memory corruption while processing key blob passed by the user.
CVE-2024-21462Media (5.5)0.09%—1 jul 2024
Transient DOS while loading the TA ELF file.
CVE-2023-28578Alta (7.8)0.12%—4 mar 2024
Memory corruption in Core Services while executing the command for removing a single event listener.
CVE-2023-33076Alta (7.8)0.11%—6 feb 2024
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.
CVE-2023-33072Alta (7.8)0.11%—6 feb 2024
Memory corruption in Core while processing control functions.
CVE-2023-33060Media (5.5)0.10%—6 feb 2024
Transient DOS in Core when DDR memory check is called while DDR is not initialized.
CVE-2023-33058Crítica (9.1)0.36%—6 feb 2024
Information disclosure in Modem while processing SIB5.
CVE-2023-33057Alta (7.5)0.32%—6 feb 2024
Transient DOS in Multi-Mode Call Processor while processing UE policy container.
CVE-2023-33049Alta (7.5)0.32%—6 feb 2024
Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.
CVE-2023-33046Alta (7)0.08%—6 feb 2024
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.
CVE-2023-33110Alta (7)0.08%—2 ene 2024
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation4
  2. T1059 Command and Scripting Interpreter3
  3. T1190 Exploit Public-Facing Application3
  4. T1210 Exploitation of Remote Services2
  5. T1005 Data from Local System1
  6. T1040 Network Sniffing1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Qualcomm