Qca6310 Firmware
by Qualcomm
CVEs (388)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-35116 | Hig | 0.50 | 7.7 | 0.00 | Jun 14, 2022 | APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-21430 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | ||
| CVE-2024-33058 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP. | ||
| CVE-2024-53027 | Hig | 0.49 | 7.5 | 0.00 | Mar 3, 2025 | Transient DOS may occur while processing the country IE. | ||
| CVE-2024-33051 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. | ||
| CVE-2024-33048 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2024 | Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. | ||
| CVE-2024-33014 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. | ||
| CVE-2024-23353 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | ||
| CVE-2024-21479 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS during music playback of ALAC content. | ||
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43533 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. | ||
| CVE-2023-43511 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | ||
| CVE-2023-33109 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. | ||
| CVE-2023-33062 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS in WLAN Firmware while parsing a BTM request. | ||
| CVE-2023-33080 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. | ||
| CVE-2023-28588 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Bluetooth Host while rfc slot allocation. | ||
| CVE-2023-33027 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in WLAN Firmware while parsing rsn ies. | ||
| CVE-2023-24847 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in Modem while allocating DSM items. | ||
| CVE-2023-33015 | Hig | 0.49 | 7.5 | 0.00 | Sep 5, 2023 | Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame. |
- risk 0.50cvss 7.7epss 0.00
APK can load a crafted model into the CDSP which can lead to a compromise of CDSP and other APK`s data executing there in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- risk 0.49cvss 7.5epss 0.00
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while processing the country IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ESP IE from beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
- risk 0.49cvss 7.5epss 0.00
Transient DOS during music playback of ALAC content.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing a BTM request.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Bluetooth Host while rfc slot allocation.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing rsn ies.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Modem while allocating DSM items.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
Page 12 of 20