Wcn785x 5 Firmware
by Qualcomm
CVEs (83)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-22060 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Assertion occurs while processing Reconfiguration message due to improper validation | ||
| CVE-2022-40504 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | ||
| CVE-2022-40508 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. | ||
| CVE-2022-34144 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem during OSI decode scheduling. | ||
| CVE-2022-33305 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. | ||
| CVE-2022-33304 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet. | ||
| CVE-2022-33270 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message. | ||
| CVE-2022-25739 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call | ||
| CVE-2022-33273 | Hig | 0.47 | 7.3 | 0.00 | May 2, 2023 | Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation. | ||
| CVE-2022-40529 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Memory corruption due to improper access control in kernel while processing a mapping request from root process. | ||
| CVE-2022-40523 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Information disclosure in Kernel due to indirect branch misprediction. | ||
| CVE-2022-22076 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. | ||
| CVE-2023-33024 | Med | 0.44 | 6.7 | 0.00 | Dec 5, 2023 | Memory corruption while sending SMS from AP firmware. | ||
| CVE-2022-33263 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption due to use after free in Core when multiple DCI clients register and deregister. | ||
| CVE-2022-33226 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications. | ||
| CVE-2022-33224 | Med | 0.44 | 6.7 | 0.00 | Jun 6, 2023 | Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries. | ||
| CVE-2022-33281 | Med | 0.44 | 6.7 | 0.00 | May 2, 2023 | Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending any frames. | ||
| CVE-2022-33302 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | ||
| CVE-2022-33289 | Med | 0.44 | 6.8 | 0.00 | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | ||
| CVE-2023-28571 | Med | 0.40 | 6.1 | 0.00 | Oct 3, 2023 | Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan. |
- risk 0.49cvss 7.5epss 0.00
Assertion occurs while processing Reconfiguration message due to improper validation
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.
- risk 0.49cvss 7.5epss 0.00
Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call
- risk 0.47cvss 7.3epss 0.00
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
- risk 0.46cvss 7.1epss 0.00
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
- risk 0.46cvss 7.1epss 0.00
Information disclosure in Kernel due to indirect branch misprediction.
- risk 0.46cvss 7.1epss 0.00
information disclosure due to cryptographic issue in Core during RPMB read request.
- risk 0.44cvss 6.7epss 0.00
Memory corruption while sending SMS from AP firmware.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to use after free in Core when multiple DCI clients register and deregister.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.
- risk 0.44cvss 6.7epss 0.00
Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending any frames.
- risk 0.44cvss 6.8epss 0.00
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
- risk 0.44cvss 6.8epss 0.00
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
Page 4 of 5