Qualcomm
Qualcomm Wcn3999 Firmware: vulnerabilidades y CVE
Qualcomm Wcn3999 Firmware tiene 286 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 37 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE286
Últimos 12 meses1
Críticas37
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22071 | Alta (7.8) | 0.46% | ⚠ Explotación activa | 14 jun 2022 | Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2020-11261 | Alta (7.8) | 1.6% | ⚠ Explotación activa | 9 jun 2021 | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT,… |
| CVE-2021-1906 | Media (5.5) | 0.52% | ⚠ Explotación activa | 7 may 2021 | Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… |
| CVE-2021-1905 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 7 may 2021 | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27054 | Alta (7.8) | 0.09% | — | 9 oct 2025 | Memory corruption while processing a malformed license file during reboot. |
| CVE-2025-21481 | Alta (7.8) | 0.07% | — | 24 sept 2025 | Memory corruption while performing private key encryption in trusted application. |
| CVE-2025-21482 | Alta (7.1) | 0.08% | — | 24 sept 2025 | Cryptographic issue while performing RSA PKCS padding decoding. |
| CVE-2025-27066 | Alta (7.5) | 0.28% | — | 6 ago 2025 | Transient DOS while processing an ANQP message. |
| CVE-2025-21465 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while processing the hash segment in an MBN file. |
| CVE-2025-21464 | Media (6.5) | 0.09% | — | 6 ago 2025 | Information disclosure while reading data from an image using specified offset and size parameters. |
| CVE-2024-43046 | Media (5.5) | 0.11% | — | 7 abr 2025 | There may be information disclosure during memory re-allocation in TZ Secure OS. |
| CVE-2024-43051 | Media (5.5) | 0.11% | — | 3 mar 2025 | Information disclosure while deriving keys for a session for any Widevine use case. |
| CVE-2024-33056 | Alta (7.8) | 0.10% | — | 2 dic 2024 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| CVE-2024-33051 | Alta (7.5) | 0.30% | — | 2 sept 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| CVE-2024-33016 | Media (6.8) | 0.15% | — | 2 sept 2024 | memory corruption when an invalid firehose patch command is invoked. |
| CVE-2024-23362 | Alta (7.1) | 0.12% | — | 2 sept 2024 | Cryptographic issue while parsing RSA keys in COBR format. |
| CVE-2024-23356 | Alta (7.8) | 0.11% | — | 5 ago 2024 | Memory corruption during session sign renewal request calls in HLOS. |
| CVE-2024-21469 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption when an invoke call and a TEE call are bound for the same trusted application. |
| CVE-2024-21465 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while processing key blob passed by the user. |
| CVE-2024-21462 | Media (5.5) | 0.09% | — | 1 jul 2024 | Transient DOS while loading the TA ELF file. |
| CVE-2024-21461 | Alta (7.8) | 0.10% | — | 1 jul 2024 | Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
| CVE-2023-43542 | Alta (7.8) | 0.10% | — | 3 jun 2024 | Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. |
| CVE-2023-33023 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption while processing finish_sign command to pass a rsp buffer. |
| CVE-2023-28547 | Alta (7.8) | 0.11% | — | 1 abr 2024 | Memory corruption in SPS Application while requesting for public key in sorter TA. |
| CVE-2023-33066 | Alta (7.8) | 0.11% | — | 4 mar 2024 | Memory corruption in Audio while processing RT proxy port register driver. |
| CVE-2023-28578 | Alta (7.8) | 0.12% | — | 4 mar 2024 | Memory corruption in Core Services while executing the command for removing a single event listener. |
| CVE-2023-43536 | Alta (7.5) | 0.32% | — | 6 feb 2024 | Transient DOS while parse fils IE with length equal to 1. |
| CVE-2023-33072 | Alta (7.8) | 0.11% | — | 6 feb 2024 | Memory corruption in Core while processing control functions. |
| CVE-2023-43511 | Alta (7.5) | 0.32% | — | 2 ene 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| CVE-2023-33110 | Alta (7) | 0.08% | — | 2 ene 2024 | The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close… |
| CVE-2023-33109 | Alta (7.5) | 0.34% | — | 2 ene 2024 | Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. |
| CVE-2023-33062 | Alta (7.5) | 0.34% | — | 2 ene 2024 | Transient DOS in WLAN Firmware while parsing a BTM request. |
| CVE-2023-33033 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in Audio during playback with speaker protection. |
| CVE-2023-33032 | Alta (7.8) | 0.12% | — | 2 ene 2024 | Memory corruption in TZ Secure OS while requesting a memory allocation from TA region. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.