Qca4010 Firmware
by Qualcomm
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25727 | Cri | 0.64 | 9.8 | 0.00 | Nov 15, 2022 | Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music | ||
| CVE-2022-25718 | Cri | 0.59 | 9.1 | 0.00 | Oct 19, 2022 | Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | ||
| CVE-2020-11269 | Hig | 0.57 | 8.8 | 0.00 | Feb 22, 2021 | Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… | ||
| CVE-2023-21628 | Hig | 0.55 | 8.4 | 0.00 | Jun 6, 2023 | Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | ||
| CVE-2022-25655 | Hig | 0.55 | 8.4 | 0.00 | Mar 10, 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. | ||
| CVE-2021-30288 | Hig | 0.55 | 8.4 | 0.00 | Oct 20, 2021 | Possible stack overflow due to improper length check of TLV while copying the TLV to a local stack variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,… | ||
| CVE-2023-21625 | Hig | 0.53 | 8.2 | 0.00 | Aug 8, 2023 | Information disclosure in Network Services due to buffer over-read while the device receives DNS response. | ||
| CVE-2022-40505 | Hig | 0.53 | 8.2 | 0.00 | May 2, 2023 | Information disclosure due to buffer over-read in Modem while parsing DNS hostname. | ||
| CVE-2022-33291 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length. | ||
| CVE-2022-33287 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet. | ||
| CVE-2022-33222 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure due to buffer over-read while parsing DNS response packets in Modem. | ||
| CVE-2022-25730 | Hig | 0.53 | 8.2 | 0.00 | Apr 13, 2023 | Information disclosure in modem due to improper check of IP type while processing DNS server query | ||
| CVE-2022-33229 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets. | ||
| CVE-2022-25738 | Hig | 0.53 | 8.2 | 0.00 | Feb 12, 2023 | Information disclosure in modem due to buffer over-red while performing checksum of packet received | ||
| CVE-2022-25719 | Hig | 0.53 | 8.2 | 0.00 | Oct 19, 2022 | Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,… | ||
| CVE-2023-28565 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while handling command streams through WMI interfaces. | ||
| CVE-2023-28560 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload. | ||
| CVE-2023-28559 | Hig | 0.51 | 7.8 | 0.00 | Sep 5, 2023 | Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. | ||
| CVE-2019-14135 | Hig | 0.51 | 7.8 | 0.00 | Apr 16, 2020 | Possible integer overflow to buffer overflow in WLAN while parsing nonstandard NAN IE messages. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,… | ||
| CVE-2022-25731 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Information disclosure in modem due to buffer over-read while processing packets from DNS server |
- risk 0.64cvss 9.8epss 0.00
Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music
- risk 0.59cvss 9.1epss 0.00
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
- risk 0.57cvss 8.8epss 0.00
Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
- risk 0.55cvss 8.4epss 0.00
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
- risk 0.55cvss 8.4epss 0.00
Possible stack overflow due to improper length check of TLV while copying the TLV to a local stack variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
- risk 0.53cvss 8.2epss 0.00
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in Modem while parsing DNS hostname.
- risk 0.53cvss 8.2epss 0.00
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.
- risk 0.53cvss 8.2epss 0.00
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet.
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read while parsing DNS response packets in Modem.
- risk 0.53cvss 8.2epss 0.00
Information disclosure in modem due to improper check of IP type while processing DNS server query
- risk 0.53cvss 8.2epss 0.00
Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets.
- risk 0.53cvss 8.2epss 0.00
Information disclosure in modem due to buffer over-red while performing checksum of packet received
- risk 0.53cvss 8.2epss 0.00
Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.
- risk 0.51cvss 7.8epss 0.00
Possible integer overflow to buffer overflow in WLAN while parsing nonstandard NAN IE messages. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…
- risk 0.49cvss 7.5epss 0.00
Information disclosure in modem due to buffer over-read while processing packets from DNS server
Page 1 of 2