315 5g Iot Modem Firmware
by Qualcomm
CVEs (115)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-33264 | Hig | 0.51 | 7.9 | 0.00 | Jun 6, 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. | ||
| CVE-2025-27066 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing an ANQP message. | ||
| CVE-2025-21477 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing CCCH data when NW sends data with invalid length. | ||
| CVE-2025-21452 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2025 | Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network. | ||
| CVE-2025-21454 | Hig | 0.49 | 7.5 | 0.00 | Jul 8, 2025 | Transient DOS while processing received beacon frame. | ||
| CVE-2025-21448 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS may occur while parsing SSID in action frames. | ||
| CVE-2025-21430 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2025 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | ||
| CVE-2024-33014 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while parsing ESP IE from beacon/probe response frame. | ||
| CVE-2024-23353 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | ||
| CVE-2024-23352 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2024 | Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA. | ||
| CVE-2023-43529 | Hig | 0.49 | 7.5 | 0.00 | May 6, 2024 | Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. | ||
| CVE-2023-33101 | Hig | 0.49 | 7.5 | 0.00 | Apr 1, 2024 | Transient DOS while processing DL NAS TRANSPORT message with payload length 0. | ||
| CVE-2023-33099 | Hig | 0.49 | 7.5 | 0.00 | Apr 1, 2024 | Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR. | ||
| CVE-2023-33104 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing PDU Release command with a parameter PDU ID out of range. | ||
| CVE-2023-33096 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16. | ||
| CVE-2023-33095 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR. | ||
| CVE-2023-33086 | Hig | 0.49 | 7.5 | 0.00 | Mar 4, 2024 | Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers. | ||
| CVE-2023-43536 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS while parse fils IE with length equal to 1. | ||
| CVE-2023-43533 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. | ||
| CVE-2023-33057 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in Multi-Mode Call Processor while processing UE policy container. |
- risk 0.51cvss 7.9epss 0.00
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing an ANQP message.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing CCCH data when NW sends data with invalid length.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing received beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS may occur while parsing SSID in action frames.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parsing ESP IE from beacon/probe response frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
- risk 0.49cvss 7.5epss 0.00
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing DL NAS TRANSPORT message with payload length 0.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
- risk 0.49cvss 7.5epss 0.00
Transient DOS while parse fils IE with length equal to 1.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Multi-Mode Call Processor while processing UE policy container.
Page 4 of 6