qualcomm Vulnerabilities and Affected Products
Vulnerabilities associated with wcn3980_firmware.
Products
Clear product- wsa8830_firmware215 vulnerabilities
- wsa8835_firmware215 vulnerabilities
- wcd9380_firmware211 vulnerabilities
- fastconnect_7800_firmware197 vulnerabilities
- fastconnect_6900_firmware194 vulnerabilities
- qca6696_firmware194 vulnerabilities
- wcd9385_firmware190 vulnerabilities
- qca6574au_firmware188 vulnerabilities
- wsa8810_firmware186 vulnerabilities
- wsa8815_firmware184 vulnerabilities
- qca6391_firmware180 vulnerabilities
- qca6574a_firmware175 vulnerabilities
- wcd9370_firmware175 vulnerabilities
- qca6595au_firmware172 vulnerabilities
- qca6698aq_firmware168 vulnerabilities
- qca8081_firmware160 vulnerabilities
- wcd9375_firmware158 vulnerabilities
- wcn3980_firmware157 vulnerabilities
- qca8337_firmware155 vulnerabilities
- sa6155p_firmware154 vulnerabilities
- wcn3988_firmware153 vulnerabilities
- ar8035_firmware150 vulnerabilities
- sa8155p_firmware150 vulnerabilities
- wcd9341_firmware145 vulnerabilities
- fastconnect_6700_firmware142 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-43052HIGH | Improper Input Validation in Video Analytics and ProcessingMemory corruption while processing API calls to NPU with invalid input. CWE-20Dec 2, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33053MEDIUM | Use After Free in VideoMemory corruption when multiple threads try to unregister the CVP buffer at the same time. CWE-416Dec 2, 2024 | CVSS6.7v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33044HIGH | Improper Validation of Array Index in HypervisorMemory corruption while Configuring the SMR/S2CR register in Bypass mode. CWE-129Dec 2, 2024 | CVSS8.4v3.1 | EPSS0.104% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33040MEDIUM | Use After Free in Camera DriverMemory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access. CWE-416Dec 2, 2024 | CVSS6.7v3.1 | EPSS0.089% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33039MEDIUM | Untrusted Pointer Dereference in AudioMemory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service. CWE-822Dec 2, 2024 | CVSS6.7v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33037MEDIUM | Buffer Over-read in Neural Processing UnitInformation disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware. CWE-126Dec 2, 2024 | CVSS6.1v3.1 | EPSS0.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33036MEDIUM | Use of Out-of-range Pointer Offset in Camera DriverMemory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access. CWE-823Dec 2, 2024 | CVSS6.7v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-30299MEDIUM | Improper Input Validation in AudioPossible out of bound access in audio module due to lack of validation of user provided input. CWE-20Nov 22, 2024 | CVSS6.7v3.1 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38424HIGH | Use After Free in GPSMemory corruption during GNSS HAL process initialization. CWE-416Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38423HIGH | Buffer Copy Without Checking Size of Input in Graphics LinuxMemory corruption while processing GPU page table switch. CWE-120Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38422HIGH | Integer Overflow to Buffer Overflow in AudioMemory corruption while processing voice packet with arbitrary data received from ADSP. CWE-680Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38421HIGH | Use After Free in Graphics LinuxMemory corruption while processing GPU commands. CWE-416Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38419HIGH | Use After Free in Automotive GPUMemory corruption while invoking IOCTL calls from the use-space for HGSL memory node. CWE-416Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38415HIGH | Use After Free in Computer VisionMemory corruption while handling session errors from firmware. CWE-416Nov 4, 2024 | CVSS7.8v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38408HIGH | Cryptographic Issues in BT ControllerCryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. CWE-310Nov 4, 2024 | CVSS8.2v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38403HIGH | Buffer Over-read in WLAN FirmwareTransient DOS while parsing BTM ML IE when per STA profile is not included. | CVSS7.5v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33032MEDIUM | Improper Validation of Array Index in Camera_LinuxMemory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it. CWE-129Nov 4, 2024 | CVSS6.7v3.1 | EPSS0.102% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23385HIGH | Reachable Assertion in ModemTransient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. CWE-617Nov 4, 2024 | CVSS7.5v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43047HIGH | Use After Free in DSP ServiceMemory corruption while maintaining memory maps of HLOS memory. CWE-416Oct 7, 2024 | CVSS7.8v3.1 | EPSS0.674% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-33069HIGH | Use After Free in WLAN HostTransient DOS when transmission of management frame sent by host is not successful and error status is received in the host. CWE-416Oct 7, 2024 | CVSS7.5v3.1 | EPSS0.358% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23376MEDIUM | Use After Free in ComputerVisionMemory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call. CWE-416Oct 7, 2024 | CVSS6.7v3.1 | EPSS0.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23375MEDIUM | Buffer Copy Without Checking Size of Input (`Classic Buffer Overflow`) in RILMemory corruption during the network scan request. CWE-120Oct 7, 2024 | CVSS6.7v3.1 | EPSS0.121% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23374MEDIUM | Stack-based Buffer Overflow in Power Management ICMemory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file. | CVSS6.7v3.1 | EPSS0.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23370MEDIUM | Use After Free in Automotive MultimediaMemory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same. CWE-416Oct 7, 2024 | CVSS6.7v3.1 | EPSS0.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-21455HIGH | Untrusted Pointer Dereference in DSP ServiceMemory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver. | CVSS7.8v3.1 | EPSS0.171% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |