Home/Product/qualcomm qca6175a firmware
Product

qualcomm qca6175a firmware

131 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-47318
all versions
Transient DOS while parsing the EPTM test control message to get the test pattern.
7.5HIGH
CVE-2025-21430
all versions
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
7.5HIGH
CVE-2025-21429
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
7.5HIGH
CVE-2025-21428
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session
7.5HIGH
CVE-2024-53027
all versions
Transient DOS may occur while processing the country IE.
7.5HIGH
CVE-2024-38408
all versions
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
8.2HIGH
CVE-2024-33049
all versions
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
7.5HIGH
CVE-2024-33051
all versions
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
7.5HIGH
CVE-2024-33050
all versions
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improp
7.5HIGH
CVE-2024-33014
all versions
Transient DOS while parsing ESP IE from beacon/probe response frame.
7.5HIGH
CVE-2024-33012
all versions
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
7.5HIGH
CVE-2024-33011
all versions
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
7.5HIGH
CVE-2024-33010
all versions
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
7.5HIGH
CVE-2024-21467
all versions
Information disclosure while handling beacon probe frame during scan entry generation in client side.
6.5MEDIUM
CVE-2024-21459
all versions
Information disclosure while handling beacon or probe response frame in STA.
6.5MEDIUM
CVE-2023-43511
all versions
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTO_NONE as the n
7.5HIGH
CVE-2023-33080
all versions
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
7.5HIGH
CVE-2023-28572
all versions
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
6.6MEDIUM
CVE-2023-28553
all versions
Information Disclosure in WLAN Host when processing WMI event command.
6.1MEDIUM
CVE-2023-28571
all versions
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
6.1MEDIUM
CVE-2023-28539
all versions
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
6.6MEDIUM
CVE-2023-33020
all versions
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
7.5HIGH
CVE-2023-33019
all versions
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE
7.5HIGH
CVE-2023-28565
all versions
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
7.8HIGH
CVE-2023-28564
all versions
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
7.8HIGH
CVE-2023-28542
all versions
Memory Corruption in WLAN HOST while fetching TX status information.
7.8HIGH
CVE-2023-28541
all versions
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
7.8HIGH
CVE-2023-21656
all versions
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
7.8HIGH
CVE-2023-21628
all versions
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
8.4HIGH
CVE-2022-40532
all versions
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
8.4HIGH
CVE-2022-40531
all versions
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
8.4HIGH
CVE-2022-33245
all versions
Memory corruption in WLAN due to use after free
6.7MEDIUM
CVE-2022-25655
all versions
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
8.4HIGH
CVE-2022-40512
all versions
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
7.5HIGH
CVE-2022-34145
all versions
Transient DOS due to buffer over-read in WLAN Host while parsing frame information.
7.5HIGH
CVE-2022-33299
all versions
Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data.
7.5HIGH
CVE-2022-33290
all versions
Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed.
7.5HIGH
CVE-2022-33286
all versions
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
7.5HIGH
CVE-2022-33285
all versions
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
7.5HIGH
CVE-2022-33238
all versions
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Sna
7.5HIGH
CVE-2022-33239
all versions
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto
7.5HIGH
CVE-2022-25741
all versions
Denial of service in WLAN due to potential null pointer dereference while accessing the memory location in Snapdragon Auto, Snapdr
7.5HIGH
CVE-2022-25710
all versions
Denial of service due to null pointer dereference when GATT is disconnected in Snapdragon Auto, Snapdragon Consumer IOT, Snapdrago
7.5HIGH
CVE-2022-25749
all versions
Transient Denial-of-Service in WLAN due to buffer over-read while parsing MDNS frames. in Snapdragon Auto, Snapdragon Compute, Sna
7.5HIGH
CVE-2022-25748
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Comp
9.8CRITICAL
CVE-2022-25720
all versions
Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdrag
9.8CRITICAL
CVE-2022-25718
all versions
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Co
9.1CRITICAL
CVE-2022-22058
all versions
Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Compute, Snapd
8.4HIGH
CVE-2022-25690
all versions
Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Au
7.5HIGH
CVE-2022-25670
all versions
Denial of service in WLAN HOST due to buffer over read while unpacking frames in Snapdragon Auto, Snapdragon Compute, Snapdragon C
7.5HIGH
CVE-2022-22066
all versions
Memory corruption occurs while processing command received from HLOS due to improper length check in Snapdragon Auto, Snapdragon C
8.4HIGH
CVE-2022-22070
all versions
Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon C
7.8HIGH
CVE-2022-22062
all versions
An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snapdragon Com
8.2HIGH
CVE-2021-35135
all versions
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti
6.2MEDIUM
CVE-2021-35097
all versions
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in S
7.3HIGH
CVE-2022-22072
all versions
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2022-22065
all versions
Out of bound read in WLAN HOST due to improper length check can lead to DOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
7.5HIGH
CVE-2022-22064
all versions
Possible buffer over read due to lack of size validation while unpacking frame in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.5HIGH
CVE-2021-35119
all versions
Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snapdragon Aut
5.5MEDIUM
CVE-2021-35085
all versions
Possible buffer overflow due to lack of buffer length check during management frame Rx handling in Snapdragon Auto, Snapdragon Com
5.5MEDIUM
CVE-2021-35084
all versions
Possible out of bound read due to lack of length check of data length for a DIAG event in Snapdragon Auto, Snapdragon Compute, Sna
5.5MEDIUM
CVE-2021-35071
all versions
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of
5.5MEDIUM
CVE-2021-35117
all versions
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Co
8.2HIGH
CVE-2021-35106
all versions
Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon C
7.8HIGH
CVE-2021-35088
all versions
Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Sn
8.2HIGH
CVE-2021-35069
all versions
Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2021-30319
all versions
Possible integer overflow due to improper validation of command length parameters while processing WMI command in Snapdragon Auto,
7.8HIGH
CVE-2021-30348
all versions
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapd
6.5MEDIUM
CVE-2021-30303
all versions
Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon
7.8HIGH
CVE-2021-30259
all versions
Possible out of bound access due to improper validation of function table entries in Snapdragon Auto, Snapdragon Compute, Snapdrag
7.8HIGH
CVE-2021-1924
all versions
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon
9.0CRITICAL
CVE-2021-1903
all versions
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe res
5.3MEDIUM
CVE-2021-30310
all versions
Possible buffer overflow due to Improper validation of received CF-ACK and CF-Poll data frames in Snapdragon Auto, Snapdragon Conn
7.5HIGH
CVE-2021-1977
all versions
Possible buffer over read due to improper validation of frame length while processing AEAD decryption during ASSOC response in Sna
7.5HIGH
CVE-2020-11303
all versions
Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapd
8.6HIGH
CVE-2021-30260
all versions
Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist
8.4HIGH
CVE-2021-1974
all versions
Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapd
7.5HIGH
CVE-2021-1971
all versions
Possible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,
7.5HIGH
CVE-2021-1960
all versions
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdrago
6.5MEDIUM
CVE-2021-1956
all versions
Improper handling of ASB-U packet with L2CAP channel ID by slave host can lead to interference with piconet in Snapdragon Auto, Sn
6.5MEDIUM
CVE-2021-1941
all versions
Possible buffer over read issue due to improper length check on WPA IE string sent by peer in Snapdragon Auto, Snapdragon Compute,
7.5HIGH
CVE-2021-1935
all versions
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdra
7.1HIGH
CVE-2021-1909
all versions
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, S
7.3HIGH
CVE-2020-11301
all versions
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapd
9.1CRITICAL
CVE-2020-11264
all versions
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injectio
9.1CRITICAL
CVE-2021-1970
all versions
Possible out of bound read due to lack of length check of FT sub-elements in Snapdragon Auto, Snapdragon Compute, Snapdragon Conne
7.5HIGH
CVE-2021-1964
all versions
Possible buffer over read due to improper validation of IE size while parsing beacon from peer device in Snapdragon Auto, Snapdrag
7.5HIGH
CVE-2021-1955
all versions
Denial of service in SAP case due to improper handling of connections when association is rejected in Snapdragon Auto, Snapdragon
7.5HIGH
CVE-2021-1953
all versions
Improper handling of received malformed FTMR request frame can lead to reachable assertion while responding with FTM1 frame in Sna
7.5HIGH
CVE-2021-1943
all versions
Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response
7.5HIGH
CVE-2021-1938
all versions
Possible assertion due to improper verification while creating and deleting the peer in Snapdragon Auto, Snapdragon Compute, Snapd
7.5HIGH
CVE-2021-1907
all versions
Possible buffer overflow due to lack of length check in BA request in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity
7.5HIGH
CVE-2021-1890
all versions
Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon
8.4HIGH
CVE-2021-1889
all versions
Possible buffer overflow due to lack of length check in Trusted Application in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
8.4HIGH
CVE-2021-1888
all versions
Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon
8.4HIGH
CVE-2021-1886
all versions
Incorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon Auto, Snapd
8.4HIGH
CVE-2021-1937
all versions
Reachable assertion is possible while processing peer association WLAN message from host and nonstandard incoming packet in Snapdr
7.5HIGH
CVE-2021-1900
all versions
Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdragon Compute
8.4HIGH
CVE-2020-11304
all versions
Possible out of bound read in DRM due to improper buffer length check. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti
7.8HIGH
CVE-2020-11250
all versions
Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdrago
7.0HIGH
CVE-2020-11241
all versions
Out of bound read will happen if EAPOL Key length is less than expected while processing NAN shared key descriptor attribute in Sn
7.5HIGH
CVE-2020-11238
all versions
Possible Buffer over-read in ARP/NS parsing due to lack of check of packet length received in Snapdragon Auto, Snapdragon Compute,
7.5HIGH
CVE-2020-11235
all versions
Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto, Snapdrag
7.8HIGH
CVE-2020-11182
all versions
Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snap
9.8CRITICAL
CVE-2020-11178
all versions
Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memor
7.8HIGH
CVE-2020-11159
all versions
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame po
9.1CRITICAL
CVE-2020-11134
all versions
Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN rangin
9.8CRITICAL
CVE-2020-11126
all versions
Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon
9.1CRITICAL
CVE-2021-1925
all versions
Possible denial of service scenario due to improper handling of group management action frame in Snapdragon Auto, Snapdragon Compu
7.5HIGH
CVE-2021-1915
all versions
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2020-11294
all versions
Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon
5.9MEDIUM
CVE-2020-11293
all versions
Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer length rece
5.1MEDIUM
CVE-2020-11289
all versions
Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute,
7.8HIGH
CVE-2020-11288
all versions
Out of bound write can occur in playready while processing command due to lack of input validation in Snapdragon Auto, Snapdragon
7.8HIGH
CVE-2020-11252
all versions
Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Au
7.2HIGH
CVE-2020-11234
all versions
When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread r
8.4HIGH
CVE-2020-3664
all versions
Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snap
6.0MEDIUM
CVE-2020-11297
all versions
Denial of service in WLAN module due to improper check of subtypes in logic where excessive frames are dropped in Snapdragon Auto,
7.5HIGH
CVE-2020-11296
all versions
Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snap
7.5HIGH
CVE-2020-11281
all versions
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclos
7.5HIGH
CVE-2020-11280
all versions
Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parameter IE due
7.5HIGH
CVE-2020-11278
all versions
Possible denial of service while handling host WMI command due to improper validation in Snapdragon Auto, Snapdragon Compute, Snap
7.5HIGH
CVE-2020-11276
all versions
Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation
9.1CRITICAL
CVE-2020-11275
all versions
Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapd
9.1CRITICAL
CVE-2020-11272
all versions
Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version
9.8CRITICAL
CVE-2020-11270
all versions
Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM
7.5HIGH
CVE-2020-11269
all versions
Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Aut
8.8HIGH
CVE-2020-11204
all versions
Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for par
7.8HIGH
CVE-2020-11198
all versions
Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage o
6.7MEDIUM
CVE-2020-11195
all versions
Out of bound write and read in TA while processing command from NS side due to improper length check on command and response buffe
7.8HIGH
CVE-2020-11119
all versions
Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload in Snapdra
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin