Sg8275p Firmware
by Qualcomm
CVEs (138)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43539 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame. | ||
| CVE-2023-33105 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2024 | Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number. | ||
| CVE-2023-33104 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing PDU Release command with a parameter PDU ID out of range. | ||
| CVE-2023-33103 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing CAG info IE received from NW. | ||
| CVE-2023-33096 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16. | ||
| CVE-2023-33095 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR. | ||
| CVE-2023-33086 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers. | ||
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43523 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while processing 11AZ RTT management action frame received through OTA. | ||
| CVE-2023-43522 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. | ||
| CVE-2023-33057 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in Multi-Mode Call Processor while processing UE policy container. | ||
| CVE-2023-33049 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage. | ||
| CVE-2023-43511 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | ||
| CVE-2023-33112 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element. | ||
| CVE-2023-33097 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS in WLAN Firmware while processing a FTMR frame. | ||
| CVE-2023-33089 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS when processing a NULL buffer while parsing WLAN vdev. | ||
| CVE-2023-28588 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Bluetooth Host while rfc slot allocation. | ||
| CVE-2023-33047 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware while parsing no-inherit IES. | ||
| CVE-2023-33026 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in WLAN Firmware while parsing a NAN management frame. | ||
| CVE-2024-21469 | Hig | 0.47 | 7.3 | 0.00 | Jul 1, 2024 | Memory corruption when an invoke call and a TEE call are bound for the same trusted application. |
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing CAG info IE received from NW.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing 11AZ RTT management action frame received through OTA.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Multi-Mode Call Processor while processing UE policy container.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while processing a FTMR frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Bluetooth Host while rfc slot allocation.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing no-inherit IES.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing a NAN management frame.
- risk 0.47cvss 7.3epss 0.00
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
Page 6 of 7