Wcn685x 1 Firmware
by Qualcomm
CVEs (93)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28560 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. | ||
| CVE-2023-21670 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode. | ||
| CVE-2023-21657 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memoru corruption in Audio when ADSP sends input during record use case. | ||
| CVE-2023-21656 | Hig | 0.51 | 7.8 | 0.00 | Jun 6, 2023 | Memory corruption in WLAN HOST while receiving an WMI event from firmware. | ||
| CVE-2022-33264 | Hig | 0.51 | 7.9 | 0.00 | Jun 6, 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. | ||
| CVE-2022-25713 | Hig | 0.51 | 7.8 | 0.00 | May 2, 2023 | Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key. | ||
| CVE-2023-33081 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast. | ||
| CVE-2023-33080 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. | ||
| CVE-2023-33044 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Data modem while handling TLB control messages from the Network. | ||
| CVE-2023-33043 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Modem when a Beam switch request is made with a non-configured BWP. | ||
| CVE-2023-33042 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Modem after RRC Setup message is received. | ||
| CVE-2023-33041 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids. | ||
| CVE-2023-33061 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame. | ||
| CVE-2023-33056 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE. | ||
| CVE-2023-33048 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware while parsing t2lm buffers. | ||
| CVE-2023-33047 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2023 | Transient DOS in WLAN Firmware while parsing no-inherit IES. | ||
| CVE-2023-33027 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in WLAN Firmware while parsing rsn ies. | ||
| CVE-2023-33026 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in WLAN Firmware while parsing a NAN management frame. | ||
| CVE-2023-28555 | Hig | 0.49 | 7.5 | 0.00 | Aug 8, 2023 | Transient DOS in Audio while remapping channel buffer in media codec decoding. | ||
| CVE-2023-21661 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS while parsing WLAN beacon or probe-response frame. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
- risk 0.51cvss 7.8epss 0.00
Memoru corruption in Audio when ADSP sends input during record use case.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
- risk 0.51cvss 7.9epss 0.00
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Data modem while handling TLB control messages from the Network.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Modem after RRC Setup message is received.
- risk 0.49cvss 7.5epss 0.00
Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing t2lm buffers.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing no-inherit IES.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing rsn ies.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing a NAN management frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Audio while remapping channel buffer in media codec decoding.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing WLAN beacon or probe-response frame.
Page 3 of 5