Qca6430 Firmware
by Qualcomm
CVEs (585)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11252 | Hig | 0.47 | 7.2 | 0.00 | Apr 7, 2021 | Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,… | ||
| CVE-2025-21422 | Hig | 0.46 | 7.1 | 0.00 | Jul 8, 2025 | Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. | ||
| CVE-2024-23362 | Hig | 0.46 | 7.1 | 0.00 | Sep 2, 2024 | Cryptographic issue while parsing RSA keys in COBR format. | ||
| CVE-2024-21462 | Hig | 0.46 | 7.1 | 0.00 | Jul 1, 2024 | Transient DOS while loading the TA ELF file. | ||
| CVE-2023-33036 | Hig | 0.46 | 7.1 | 0.00 | Jan 2, 2024 | Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call. | ||
| CVE-2023-33070 | Hig | 0.46 | 7.1 | 0.00 | Dec 5, 2023 | Transient DOS in Automotive OS due to improper authentication to the secure IO calls. | ||
| CVE-2023-28556 | Hig | 0.46 | 7.1 | 0.00 | Nov 7, 2023 | Cryptographic issue in HLOS during key management. | ||
| CVE-2023-21626 | Hig | 0.46 | 7.1 | 0.00 | Aug 8, 2023 | Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key. | ||
| CVE-2022-40529 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Memory corruption due to improper access control in kernel while processing a mapping request from root process. | ||
| CVE-2022-40523 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | Information disclosure in Kernel due to indirect branch misprediction. | ||
| CVE-2022-22076 | Hig | 0.46 | 7.1 | 0.00 | Jun 6, 2023 | information disclosure due to cryptographic issue in Core during RPMB read request. | ||
| CVE-2021-35101 | Hig | 0.46 | 7.1 | 0.00 | Jun 14, 2022 | Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile | ||
| CVE-2021-1935 | Hig | 0.46 | 7.1 | 0.00 | Sep 9, 2021 | Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon… | ||
| CVE-2020-11262 | Hig | 0.46 | 7.0 | 0.00 | Jun 9, 2021 | A race between command submission and destroying the context can cause an invalid context being added to the list leads to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon… | ||
| CVE-2020-11250 | Hig | 0.46 | 7.0 | 0.00 | Jun 9, 2021 | Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon… | ||
| CVE-2020-11290 | Hig | 0.46 | 7.0 | 0.00 | Mar 17, 2021 | Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2020-11203 | Hig | 0.46 | 7.1 | 0.00 | Feb 22, 2021 | Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | ||
| CVE-2026-24076 | Med | 0.44 | 6.7 | 0.00 | Aug 4, 2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. | ||
| CVE-2025-59611 | Med | 0.44 | 6.7 | 0.00 | Jun 1, 2026 | Memory corruption in diagnostic services due to absence of input validation | ||
| CVE-2024-33016 | Med | 0.44 | 6.8 | 0.00 | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. |
- risk 0.47cvss 7.2epss 0.00
Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue while parsing RSA keys in COBR format.
- risk 0.46cvss 7.1epss 0.00
Transient DOS while loading the TA ELF file.
- risk 0.46cvss 7.1epss 0.00
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call.
- risk 0.46cvss 7.1epss 0.00
Transient DOS in Automotive OS due to improper authentication to the secure IO calls.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue in HLOS during key management.
- risk 0.46cvss 7.1epss 0.00
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
- risk 0.46cvss 7.1epss 0.00
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
- risk 0.46cvss 7.1epss 0.00
Information disclosure in Kernel due to indirect branch misprediction.
- risk 0.46cvss 7.1epss 0.00
information disclosure due to cryptographic issue in Core during RPMB read request.
- risk 0.46cvss 7.1epss 0.00
Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile
- risk 0.46cvss 7.1epss 0.00
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon…
- risk 0.46cvss 7.0epss 0.00
A race between command submission and destroying the context can cause an invalid context being added to the list leads to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…
- risk 0.46cvss 7.0epss 0.00
Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…
- risk 0.46cvss 7.0epss 0.00
Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.46cvss 7.1epss 0.00
Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when processing registry values with incorrect types using a direct query method.
- risk 0.44cvss 6.7epss 0.00
Memory corruption in diagnostic services due to absence of input validation
- risk 0.44cvss 6.8epss 0.00
memory corruption when an invalid firehose patch command is invoked.
Page 23 of 30