Qcn5021 Firmware
by Qualcomm
CVEs (148)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28548 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART. | ||
| CVE-2023-22387 | Hig | 0.51 | 7.8 | 0.00 | Jul 4, 2023 | Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. | ||
| CVE-2021-35103 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2022 | Possible out of bound write due to improper validation of number of timer values received from firmware while syncing timers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired… | ||
| CVE-2021-1950 | Hig | 0.51 | 7.8 | 0.00 | Apr 1, 2022 | Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking | ||
| CVE-2021-35069 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2022 | Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired… | ||
| CVE-2021-30303 | Hig | 0.51 | 7.8 | 0.00 | Jan 3, 2022 | Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… | ||
| CVE-2020-11235 | Hig | 0.51 | 7.8 | 0.00 | Jun 9, 2021 | Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… | ||
| CVE-2021-1915 | Hig | 0.51 | 7.8 | 0.00 | May 7, 2021 | Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… | ||
| CVE-2020-11289 | Hig | 0.51 | 7.8 | 0.00 | May 7, 2021 | Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon… | ||
| CVE-2020-11204 | Hig | 0.51 | 7.8 | 0.00 | Feb 22, 2021 | Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for parameters that are read from shared MSG RAM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon… | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-21448 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. | ||
| CVE-2024-33014 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. | ||
| CVE-2023-33105 | Hig | 0.49 | 7.5 | 0.01 | Mar 4, 2024 | Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number. | ||
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43522 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. | ||
| CVE-2023-43511 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | ||
| CVE-2023-33109 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. | ||
| CVE-2023-33062 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS in WLAN Firmware while parsing a BTM request. | ||
| CVE-2023-33098 | Hig | 0.49 | 7.5 | 0.00 | Dec 5, 2023 | Transient DOS while parsing WPA IES, when it is passed with length more than expected size. |
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.
- risk 0.51cvss 7.8epss 0.00
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
- risk 0.51cvss 7.8epss 0.00
Possible out of bound write due to improper validation of number of timer values received from firmware while syncing timers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired…
- risk 0.51cvss 7.8epss 0.00
Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking
- risk 0.51cvss 7.8epss 0.00
Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired…
- risk 0.51cvss 7.8epss 0.00
Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
- risk 0.51cvss 7.8epss 0.00
Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
- risk 0.51cvss 7.8epss 0.00
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
- risk 0.51cvss 7.8epss 0.00
Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
- risk 0.51cvss 7.8epss 0.00
Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for parameters that are read from shared MSG RAM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing SSID in action frames.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ESP IE from beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware while parsing a BTM request.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing WPA IES, when it is passed with length more than expected size.
Page 4 of 8