VYPR

Aqt1000 Firmware

by Qualcomm

CVEs (620)

  • CVE-2023-43538CriJun 3, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.

  • CVE-2023-28578CriMar 4, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core Services while executing the command for removing a single event listener.

  • CVE-2023-33072CriFeb 6, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core while processing control functions.

  • CVE-2023-33032CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

  • CVE-2023-33030CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in HLOS while running playready use-case.

  • CVE-2023-21651CriAug 8, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.

  • CVE-2022-33288CriApr 13, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.

  • CVE-2022-33269CriApr 13, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.

  • CVE-2022-33231CriApr 13, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to double free in core while initializing the encryption key.

  • CVE-2022-33257CriMar 10, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.

  • CVE-2022-33232CriFeb 12, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.

  • CVE-2021-35122CriSep 2, 2022
    risk 0.60cvss 9.3epss 0.00

    Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-35090CriJun 14, 2022
    risk 0.60cvss 9.3epss 0.00

    Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-1942CriApr 1, 2022
    risk 0.60cvss 9.3epss 0.00

    Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables,…

  • CVE-2020-11301CriSep 8, 2021
    risk 0.60cvss 9.1epss 0.11

    Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2020-11264CriSep 8, 2021
    risk 0.60cvss 9.1epss 0.13

    Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2023-43551CriJun 3, 2024
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.

  • CVE-2023-33054CriDec 5, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.

  • CVE-2023-28540CriOct 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

  • CVE-2021-30342CriJun 14, 2022
    risk 0.59cvss 9.1epss 0.00

    Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

Page 3 of 31