Qcn6224 Firmware
by Qualcomm
CVEs (463)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45556 | Med | 0.42 | 6.5 | 0.00 | Apr 7, 2025 | Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR. | ||
| CVE-2024-23350 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2024 | Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network. | ||
| CVE-2024-21467 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2024 | Information disclosure while handling beacon probe frame during scan entry generation in client side. | ||
| CVE-2024-21459 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2024 | Information disclosure while handling beacon or probe response frame in STA. | ||
| CVE-2024-21458 | Med | 0.42 | 6.5 | 0.00 | Jul 1, 2024 | Information disclosure while handling SA query action frame. | ||
| CVE-2024-21457 | Med | 0.42 | 6.5 | 0.00 | Jul 1, 2024 | INformation disclosure while handling Multi-link IE in beacon frame. | ||
| CVE-2024-21456 | Med | 0.42 | 6.5 | 0.00 | Jul 1, 2024 | Information Disclosure while parsing beacon frame in STA. | ||
| CVE-2023-43537 | Med | 0.42 | 6.5 | 0.00 | Jun 3, 2024 | Information disclosure while handling T2LM Action Frame in WLAN Host. | ||
| CVE-2025-47331 | Med | 0.40 | 6.1 | 0.00 | Jan 7, 2026 | Information disclosure while processing a firmware event. | ||
| CVE-2025-27064 | Med | 0.40 | 6.1 | 0.00 | Nov 4, 2025 | Information disclosure while registering commands from clients with diag through diagHal. | ||
| CVE-2025-21457 | Med | 0.40 | 6.1 | 0.00 | Aug 6, 2025 | Information disclosure while opening a fastrpc session when domain is not sanitized. | ||
| CVE-2025-21433 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. | ||
| CVE-2024-45551 | Med | 0.40 | 6.2 | 0.00 | Apr 7, 2025 | Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass. | ||
| CVE-2024-38417 | Med | 0.40 | 6.1 | 0.00 | Feb 3, 2025 | Information disclosure while processing IO control commands. | ||
| CVE-2024-38416 | Med | 0.40 | 6.1 | 0.00 | Feb 3, 2025 | Information disclosure during audio playback. | ||
| CVE-2024-33067 | Med | 0.40 | 6.1 | 0.00 | Jan 6, 2025 | Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. | ||
| CVE-2024-23357 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | ||
| CVE-2023-43528 | Med | 0.40 | 6.1 | 0.00 | May 6, 2024 | Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. | ||
| CVE-2023-33065 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2024 | Information disclosure in Audio while accessing AVCS services from ADSP payload. | ||
| CVE-2023-28569 | Med | 0.40 | 6.1 | 0.00 | Nov 7, 2023 | Information disclosure in WLAN HAL while handling command through WMI interfaces. |
- risk 0.42cvss 6.5epss 0.00
Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.
- risk 0.42cvss 6.5epss 0.00
Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling beacon probe frame during scan entry generation in client side.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling beacon or probe response frame in STA.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling SA query action frame.
- risk 0.42cvss 6.5epss 0.00
INformation disclosure while handling Multi-link IE in beacon frame.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure while parsing beacon frame in STA.
- risk 0.42cvss 6.5epss 0.00
Information disclosure while handling T2LM Action Frame in WLAN Host.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing a firmware event.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while registering commands from clients with diag through diagHal.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while opening a fastrpc session when domain is not sanitized.
- risk 0.40cvss 6.2epss 0.00
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
- risk 0.40cvss 6.2epss 0.00
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while processing IO control commands.
- risk 0.40cvss 6.1epss 0.00
Information disclosure during audio playback.
- risk 0.40cvss 6.1epss 0.00
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
- risk 0.40cvss 6.2epss 0.00
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
- risk 0.40cvss 6.1epss 0.00
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in Audio while accessing AVCS services from ADSP payload.
- risk 0.40cvss 6.1epss 0.00
Information disclosure in WLAN HAL while handling command through WMI interfaces.
Page 22 of 24