VYPR

Qca6431 Firmware

by Qualcomm

CVEs (432)

  • CVE-2020-11204HigFeb 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for parameters that are read from shared MSG RAM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2020-11195HigFeb 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Out of bound write and read in TA while processing command from NS side due to improper length check on command and response buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2020-11194HigFeb 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible out of bound access in TA while processing a command from NS side due to improper length check of response buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired…

  • CVE-2020-11181HigJan 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Out of bound access issue while handling cvp process control command due to improper validation of buffer pointer received from HLOS in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2024-45549HigApr 7, 2025
    risk 0.50cvss 7.7epss 0.00

    Information disclosure while creating MQ channels.

  • CVE-2023-21652HigAug 8, 2023
    risk 0.50cvss 7.7epss 0.00

    Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.

  • CVE-2022-22069HigSep 2, 2022
    risk 0.50cvss 7.7epss 0.00

    Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2025-27066HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing an ANQP message.

  • CVE-2025-21452HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.

  • CVE-2025-21446HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.

  • CVE-2025-21448HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while parsing SSID in action frames.

  • CVE-2025-21435HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while parsing extended IE in beacon.

  • CVE-2025-21429HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.

  • CVE-2024-33058HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.

  • CVE-2024-33069HigOct 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.

  • CVE-2024-33051HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

  • CVE-2024-33048HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

  • CVE-2024-23364HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).

  • CVE-2024-33014HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing ESP IE from beacon/probe response frame.

  • CVE-2024-23353HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.

Page 13 of 22