Snapdragon X70 Modem Rf System Firmware
by Qualcomm
CVEs (74)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33049 | Hig | 0.49 | 7.5 | 0.00 | Feb 6, 2024 | Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage. | ||
| CVE-2023-33040 | Hig | 0.49 | 7.5 | 0.00 | Jan 2, 2024 | Transient DOS in Data Modem during DTLS handshake. | ||
| CVE-2023-33014 | Hig | 0.49 | 7.6 | 0.00 | Jan 2, 2024 | Information disclosure in Core services while processing a Diag command. | ||
| CVE-2023-33044 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Data modem while handling TLB control messages from the Network. | ||
| CVE-2023-33043 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Modem when a Beam switch request is made with a non-configured BWP. | ||
| CVE-2023-33042 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2023 | Transient DOS in Modem after RRC Setup message is received. | ||
| CVE-2023-24847 | Hig | 0.49 | 7.5 | 0.00 | Oct 3, 2023 | Transient DOS in Modem while allocating DSM items. | ||
| CVE-2022-40538 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network. | ||
| CVE-2022-40536 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. | ||
| CVE-2022-40521 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to improper authorization in Modem | ||
| CVE-2022-33251 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2023 | Transient DOS due to reachable assertion in Modem because of invalid network configuration. | ||
| CVE-2022-40504 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | ||
| CVE-2022-40508 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. | ||
| CVE-2022-34144 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to reachable assertion in Modem during OSI decode scheduling. | ||
| CVE-2022-33305 | Hig | 0.49 | 7.5 | 0.00 | May 2, 2023 | Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. | ||
| CVE-2022-33270 | Hig | 0.49 | 7.5 | 0.00 | Apr 13, 2023 | Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message. | ||
| CVE-2025-47383 | Hig | 0.47 | 7.2 | 0.00 | Mar 2, 2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | ||
| CVE-2024-21469 | Hig | 0.47 | 7.3 | 0.00 | Jul 1, 2024 | Memory corruption when an invoke call and a TEE call are bound for the same trusted application. | ||
| CVE-2025-21482 | Hig | 0.46 | 7.1 | 0.00 | Sep 24, 2025 | Cryptographic issue while performing RSA PKCS padding decoding. | ||
| CVE-2024-23362 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2024 | Cryptographic issue while parsing RSA keys in COBR format. |
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Data Modem during DTLS handshake.
- risk 0.49cvss 7.6epss 0.00
Information disclosure in Core services while processing a Diag command.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Data modem while handling TLB control messages from the Network.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.
- risk 0.49cvss 7.5epss 0.01
Transient DOS in Modem after RRC Setup message is received.
- risk 0.49cvss 7.5epss 0.00
Transient DOS in Modem while allocating DSM items.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to improper authorization in Modem
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem because of invalid network configuration.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to reachable assertion in Modem during OSI decode scheduling.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
- risk 0.49cvss 7.5epss 0.00
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.
- risk 0.47cvss 7.2epss 0.00
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
- risk 0.47cvss 7.3epss 0.00
Memory corruption when an invoke call and a TEE call are bound for the same trusted application.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while performing RSA PKCS padding decoding.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while parsing RSA keys in COBR format.
Page 3 of 4