threat
engine
.sh
Back
·
··:··
Home
/
Product
/
qualcomm qca6175a firmware
Product
qualcomm qca6175a firmware
131 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-47318
all versions
Transient DOS while parsing the EPTM test control message to get the test pattern.
7.5
HIGH
CVE-2025-21430
all versions
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
7.5
HIGH
CVE-2025-21429
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
7.5
HIGH
CVE-2025-21428
all versions
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session
7.5
HIGH
CVE-2024-53027
all versions
Transient DOS may occur while processing the country IE.
7.5
HIGH
CVE-2024-38408
all versions
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
8.2
HIGH
CVE-2024-33049
all versions
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.
7.5
HIGH
CVE-2024-33051
all versions
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
7.5
HIGH
CVE-2024-33050
all versions
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improp
7.5
HIGH
CVE-2024-33014
all versions
Transient DOS while parsing ESP IE from beacon/probe response frame.
7.5
HIGH
CVE-2024-33012
all versions
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
7.5
HIGH
CVE-2024-33011
all versions
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
7.5
HIGH
CVE-2024-33010
all versions
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
7.5
HIGH
CVE-2024-21467
all versions
Information disclosure while handling beacon probe frame during scan entry generation in client side.
6.5
MEDIUM
CVE-2024-21459
all versions
Information disclosure while handling beacon or probe response frame in STA.
6.5
MEDIUM
CVE-2023-43511
all versions
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains
IPPROTO_NONE
as the n
7.5
HIGH
CVE-2023-33080
all versions
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
7.5
HIGH
CVE-2023-28572
all versions
Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.
6.6
MEDIUM
CVE-2023-28553
all versions
Information Disclosure in WLAN Host when processing WMI event command.
6.1
MEDIUM
CVE-2023-28571
all versions
Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan.
6.1
MEDIUM
CVE-2023-28539
all versions
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
6.6
MEDIUM
CVE-2023-33020
all versions
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
7.5
HIGH
CVE-2023-33019
all versions
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE
7.5
HIGH
CVE-2023-28565
all versions
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
7.8
HIGH
CVE-2023-28564
all versions
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
7.8
HIGH
CVE-2023-28542
all versions
Memory Corruption in WLAN HOST while fetching TX status information.
7.8
HIGH
CVE-2023-28541
all versions
Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.
7.8
HIGH
CVE-2023-21656
all versions
Memory corruption in WLAN HOST while receiving an WMI event from firmware.
7.8
HIGH
CVE-2023-21628
all versions
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
8.4
HIGH
CVE-2022-40532
all versions
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
8.4
HIGH
CVE-2022-40531
all versions
Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.
8.4
HIGH
CVE-2022-33245
all versions
Memory corruption in WLAN due to use after free
6.7
MEDIUM
CVE-2022-25655
all versions
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
8.4
HIGH
CVE-2022-40512
all versions
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
7.5
HIGH
CVE-2022-34145
all versions
Transient DOS due to buffer over-read in WLAN Host while parsing frame information.
7.5
HIGH
CVE-2022-33299
all versions
Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data.
7.5
HIGH
CVE-2022-33290
all versions
Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed.
7.5
HIGH
CVE-2022-33286
all versions
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames.
7.5
HIGH
CVE-2022-33285
all versions
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.
7.5
HIGH
CVE-2022-33238
all versions
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Sna
7.5
HIGH
CVE-2022-33239
all versions
Transient DOS due to loop with unreachable exit condition in WLAN firmware while parsing IPV6 extension header. in Snapdragon Auto
7.5
HIGH
CVE-2022-25741
all versions
Denial of service in WLAN due to potential null pointer dereference while accessing the memory location in Snapdragon Auto, Snapdr
7.5
HIGH
CVE-2022-25710
all versions
Denial of service due to null pointer dereference when GATT is disconnected in Snapdragon Auto, Snapdragon Consumer IOT, Snapdrago
7.5
HIGH
CVE-2022-25749
all versions
Transient Denial-of-Service in WLAN due to buffer over-read while parsing MDNS frames. in Snapdragon Auto, Snapdragon Compute, Sna
7.5
HIGH
CVE-2022-25748
all versions
Memory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Comp
9.8
CRITICAL
CVE-2022-25720
all versions
Memory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdrag
9.8
CRITICAL
CVE-2022-25718
all versions
Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Co
9.1
CRITICAL
CVE-2022-22058
all versions
Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Compute, Snapd
8.4
HIGH
CVE-2022-25690
all versions
Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Au
7.5
HIGH
CVE-2022-25670
all versions
Denial of service in WLAN HOST due to buffer over read while unpacking frames in Snapdragon Auto, Snapdragon Compute, Snapdragon C
7.5
HIGH
CVE-2022-22066
all versions
Memory corruption occurs while processing command received from HLOS due to improper length check in Snapdragon Auto, Snapdragon C
8.4
HIGH
CVE-2022-22070
all versions
Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon C
7.8
HIGH
CVE-2022-22062
all versions
An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snapdragon Com
8.2
HIGH
CVE-2021-35135
all versions
A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti
6.2
MEDIUM
CVE-2021-35097
all versions
Possible authentication bypass due to improper order of signature verification and hashing in the signature verification call in S
7.3
HIGH
CVE-2022-22072
all versions
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute,
7.8
HIGH
CVE-2022-22065
all versions
Out of bound read in WLAN HOST due to improper length check can lead to DOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
7.5
HIGH
CVE-2022-22064
all versions
Possible buffer over read due to lack of size validation while unpacking frame in Snapdragon Auto, Snapdragon Compute, Snapdragon
7.5
HIGH
CVE-2021-35119
all versions
Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snapdragon Aut
5.5
MEDIUM
CVE-2021-35085
all versions
Possible buffer overflow due to lack of buffer length check during management frame Rx handling in Snapdragon Auto, Snapdragon Com
5.5
MEDIUM
CVE-2021-35084
all versions
Possible out of bound read due to lack of length check of data length for a DIAG event in Snapdragon Auto, Snapdragon Compute, Sna
5.5
MEDIUM
CVE-2021-35071
all versions
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of
5.5
MEDIUM
CVE-2021-35117
all versions
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Co
8.2
HIGH
CVE-2021-35106
all versions
Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon C
7.8
HIGH
CVE-2021-35088
all versions
Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Sn
8.2
HIGH
CVE-2021-35069
all versions
Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute,
7.8
HIGH
CVE-2021-30319
all versions
Possible integer overflow due to improper validation of command length parameters while processing WMI command in Snapdragon Auto,
7.8
HIGH
CVE-2021-30348
all versions
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapd
6.5
MEDIUM
CVE-2021-30303
all versions
Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon
7.8
HIGH
CVE-2021-30259
all versions
Possible out of bound access due to improper validation of function table entries in Snapdragon Auto, Snapdragon Compute, Snapdrag
7.8
HIGH
CVE-2021-1924
all versions
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon
9.0
CRITICAL
CVE-2021-1903
all versions
Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe res
5.3
MEDIUM
CVE-2021-30310
all versions
Possible buffer overflow due to Improper validation of received CF-ACK and CF-Poll data frames in Snapdragon Auto, Snapdragon Conn
7.5
HIGH
CVE-2021-1977
all versions
Possible buffer over read due to improper validation of frame length while processing AEAD decryption during ASSOC response in Sna
7.5
HIGH
CVE-2020-11303
all versions
Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapd
8.6
HIGH
CVE-2021-30260
all versions
Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist
8.4
HIGH
CVE-2021-1974
all versions
Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon Auto, Snapd
7.5
HIGH
CVE-2021-1971
all versions
Possible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,
7.5
HIGH
CVE-2021-1960
all versions
Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdrago
6.5
MEDIUM
CVE-2021-1956
all versions
Improper handling of ASB-U packet with L2CAP channel ID by slave host can lead to interference with piconet in Snapdragon Auto, Sn
6.5
MEDIUM
CVE-2021-1941
all versions
Possible buffer over read issue due to improper length check on WPA IE string sent by peer in Snapdragon Auto, Snapdragon Compute,
7.5
HIGH
CVE-2021-1935
all versions
Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdra
7.1
HIGH
CVE-2021-1909
all versions
Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, S
7.3
HIGH
CVE-2020-11301
all versions
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapd
9.1
CRITICAL
CVE-2020-11264
all versions
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injectio
9.1
CRITICAL
CVE-2021-1970
all versions
Possible out of bound read due to lack of length check of FT sub-elements in Snapdragon Auto, Snapdragon Compute, Snapdragon Conne
7.5
HIGH
CVE-2021-1964
all versions
Possible buffer over read due to improper validation of IE size while parsing beacon from peer device in Snapdragon Auto, Snapdrag
7.5
HIGH
CVE-2021-1955
all versions
Denial of service in SAP case due to improper handling of connections when association is rejected in Snapdragon Auto, Snapdragon
7.5
HIGH
CVE-2021-1953
all versions
Improper handling of received malformed FTMR request frame can lead to reachable assertion while responding with FTM1 frame in Sna
7.5
HIGH
CVE-2021-1943
all versions
Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response
7.5
HIGH
CVE-2021-1938
all versions
Possible assertion due to improper verification while creating and deleting the peer in Snapdragon Auto, Snapdragon Compute, Snapd
7.5
HIGH
CVE-2021-1907
all versions
Possible buffer overflow due to lack of length check in BA request in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity
7.5
HIGH
CVE-2021-1890
all versions
Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon
8.4
HIGH
CVE-2021-1889
all versions
Possible buffer overflow due to lack of length check in Trusted Application in Snapdragon Auto, Snapdragon Compute, Snapdragon Con
8.4
HIGH
CVE-2021-1888
all versions
Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon
8.4
HIGH
CVE-2021-1886
all versions
Incorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon Auto, Snapd
8.4
HIGH
CVE-2021-1937
all versions
Reachable assertion is possible while processing peer association WLAN message from host and nonstandard incoming packet in Snapdr
7.5
HIGH
CVE-2021-1900
all versions
Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdragon Compute
8.4
HIGH
CVE-2020-11304
all versions
Possible out of bound read in DRM due to improper buffer length check. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti
7.8
HIGH
CVE-2020-11250
all versions
Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdrago
7.0
HIGH
CVE-2020-11241
all versions
Out of bound read will happen if EAPOL Key length is less than expected while processing NAN shared key descriptor attribute in Sn
7.5
HIGH
CVE-2020-11238
all versions
Possible Buffer over-read in ARP/NS parsing due to lack of check of packet length received in Snapdragon Auto, Snapdragon Compute,
7.5
HIGH
CVE-2020-11235
all versions
Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto, Snapdrag
7.8
HIGH
CVE-2020-11182
all versions
Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snap
9.8
CRITICAL
CVE-2020-11178
all versions
Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memor
7.8
HIGH
CVE-2020-11159
all versions
Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame po
9.1
CRITICAL
CVE-2020-11134
all versions
Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN rangin
9.8
CRITICAL
CVE-2020-11126
all versions
Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon
9.1
CRITICAL
CVE-2021-1925
all versions
Possible denial of service scenario due to improper handling of group management action frame in Snapdragon Auto, Snapdragon Compu
7.5
HIGH
CVE-2021-1915
all versions
Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute,
7.8
HIGH
CVE-2020-11294
all versions
Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon
5.9
MEDIUM
CVE-2020-11293
all versions
Out of bound read can happen in Widevine TA while copying data to buffer from user data due to lack of check of buffer length rece
5.1
MEDIUM
CVE-2020-11289
all versions
Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute,
7.8
HIGH
CVE-2020-11288
all versions
Out of bound write can occur in playready while processing command due to lack of input validation in Snapdragon Auto, Snapdragon
7.8
HIGH
CVE-2020-11252
all versions
Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Au
7.2
HIGH
CVE-2020-11234
all versions
When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread r
8.4
HIGH
CVE-2020-3664
all versions
Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snap
6.0
MEDIUM
CVE-2020-11297
all versions
Denial of service in WLAN module due to improper check of subtypes in logic where excessive frames are dropped in Snapdragon Auto,
7.5
HIGH
CVE-2020-11296
all versions
Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snap
7.5
HIGH
CVE-2020-11281
all versions
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclos
7.5
HIGH
CVE-2020-11280
all versions
Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parameter IE due
7.5
HIGH
CVE-2020-11278
all versions
Possible denial of service while handling host WMI command due to improper validation in Snapdragon Auto, Snapdragon Compute, Snap
7.5
HIGH
CVE-2020-11276
all versions
Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation
9.1
CRITICAL
CVE-2020-11275
all versions
Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapd
9.1
CRITICAL
CVE-2020-11272
all versions
Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version
9.8
CRITICAL
CVE-2020-11270
all versions
Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM
7.5
HIGH
CVE-2020-11269
all versions
Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Aut
8.8
HIGH
CVE-2020-11204
all versions
Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for par
7.8
HIGH
CVE-2020-11198
all versions
Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage o
6.7
MEDIUM
CVE-2020-11195
all versions
Out of bound write and read in TA while processing command from NS side due to improper length check on command and response buffe
7.8
HIGH
CVE-2020-11119
all versions
Buffer over-read can happen when the buffer length received from response handlers is more than the size of the payload in Snapdra
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin