📦 Ipq5018 Firmware

by Qualcomm

🔍 What is Ipq5018 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-40514

CRITICAL CVSS 9.8 Feb 12, 2023

This vulnerability allows remote attackers to execute arbitrary code or cause denial of service on affected devices by exploiting a buffer overflow in WLAN firmware. It affects Qualcomm chipsets used ...

CVE-2022-33279

CRITICAL CVSS 9.8 Feb 12, 2023

CVE-2022-33279 is a critical stack-based buffer overflow vulnerability in Qualcomm WLAN firmware that allows remote code execution when processing malicious WNM (Wireless Network Management) frames. A...

CVE-2021-1924

CRITICAL CVSS 9.0 Nov 12, 2021

This vulnerability allows attackers to extract RSA private keys through timing and power side-channel attacks during modular exponentiation in RSA-CRT implementations. It affects Qualcomm Snapdragon c...

CVE-2021-1976

CRITICAL CVSS 9.8 Sep 17, 2021

This critical vulnerability in Qualcomm Snapdragon chipsets allows remote code execution due to a use-after-free memory corruption flaw in Wi-Fi P2P (peer-to-peer) device address validation. Attackers...

CVE-2021-1972

CRITICAL CVSS 9.8 Sep 8, 2021

This vulnerability allows remote attackers to execute arbitrary code on affected Qualcomm Snapdragon devices due to a buffer overflow in the P2P search functionality. Attackers can exploit improper va...

CVE-2021-1965

CRITICAL CVSS 9.8 Jul 13, 2021

CVE-2021-1965 is a critical buffer overflow vulnerability in Qualcomm Snapdragon chipsets affecting multiple product lines. Attackers can exploit this by sending specially crafted MBSSID scan informat...

CVE-2020-11159

CRITICAL CVSS 9.1 Jun 9, 2021

This CVE describes a buffer over-read vulnerability in Qualcomm Snapdragon chipsets when processing WPA/RSN information elements in Wi-Fi beacon and response frames. Attackers can exploit this to read...

CVE-2020-11126

CRITICAL CVSS 9.1 Jun 9, 2021

This vulnerability allows attackers to read memory beyond intended boundaries while parsing WLAN frames in Qualcomm Snapdragon chipsets. It affects numerous Snapdragon product lines including Auto, Mo...

CVE-2020-11276

CRITICAL CVSS 9.1 Feb 22, 2021

This vulnerability is a buffer over-read in Qualcomm Snapdragon chipsets that occurs when processing Wi-Fi P2P (Peer-to-Peer) information elements and NOA (Notice of Absence) attributes in beacon and ...

CVE-2020-3667

CRITICAL CVSS 9.8 Sep 8, 2020

This is a critical buffer overflow vulnerability in Qualcomm's WPA MIC calculation that allows attackers to execute arbitrary code or cause denial of service. It affects numerous Snapdragon chipsets a...

CVE-2020-3669

CRITICAL CVSS 9.8 Sep 8, 2020

This CVE-2020-3669 is a critical buffer overflow vulnerability in Qualcomm Snapdragon chipsets' WLAN TCP/IP verification. It allows attackers to execute arbitrary code or cause denial of service by ex...

CVE-2023-21662

HIGH CVSS 7.8 Sep 5, 2023

CVE-2023-21662 is a memory corruption vulnerability in Qualcomm's Core Platform that occurs while printing response buffers in logs. This buffer overflow vulnerability could allow attackers to execute...

CVE-2023-21664

HIGH CVSS 7.8 Sep 5, 2023

This vulnerability allows memory corruption in Qualcomm's Core Platform when printing response buffers in logs. Attackers could potentially execute arbitrary code or cause denial of service. Affects d...

CVE-2022-33309

HIGH CVSS 7.5 Mar 10, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN firmware by sending specially crafted secure FTMR frames smaller than 39 bytes. The buffer ov...

CVE-2022-40530

HIGH CVSS 8.4 Mar 10, 2023

This vulnerability allows attackers to execute arbitrary code or cause denial of service on affected Qualcomm WLAN chipsets due to memory corruption during initialization. It affects devices using vul...

CVE-2022-40502

HIGH CVSS 7.5 Feb 12, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected wireless LAN (WLAN) hosts by sending specially crafted input that triggers improper validation. It affects ...

CVE-2022-40513

HIGH CVSS 7.5 Feb 12, 2023

This vulnerability in Qualcomm WLAN firmware allows an attacker to cause a denial-of-service (DoS) condition by exploiting uncontrolled resource consumption when a peer connection is freed in a non-Qo...

CVE-2022-33243

HIGH CVSS 8.4 Feb 12, 2023

CVE-2022-33243 is a memory corruption vulnerability in Qualcomm's Inter-Processor Communication (IPC) subsystem due to improper access control. This allows attackers to execute arbitrary code or cause...

CVE-2022-33277

HIGH CVSS 8.4 Feb 12, 2023

This CVE describes a buffer overflow vulnerability in Qualcomm modem firmware that allows memory corruption when processing WMI commands. Attackers could potentially execute arbitrary code on affected...

CVE-2022-33306

HIGH CVSS 7.5 Feb 12, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected wireless devices by sending specially crafted management frames with malformed information elements (IEs). ...

CVE-2022-34146

HIGH CVSS 7.5 Feb 12, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) condition in affected Qualcomm WLAN Host systems by sending specially crafted frames during defragmentation. It affects devices w...

CVE-2021-35129

HIGH CVSS 7.8 Jun 14, 2022

This vulnerability allows memory corruption in Bluetooth controllers on Qualcomm Snapdragon chipsets due to improper length validation when processing vendor-specific commands. Attackers could potenti...

CVE-2021-35088

HIGH CVSS 8.2 Apr 1, 2022

This vulnerability allows attackers to read memory beyond intended boundaries during Wi-Fi SSID information element parsing when using DFS channels on affected Qualcomm Snapdragon chipsets. Successful...

CVE-2021-35103

HIGH CVSS 7.8 Apr 1, 2022

This vulnerability allows an attacker to write data beyond allocated memory bounds in Qualcomm Snapdragon chipsets due to improper validation of timer values from firmware. It affects multiple Snapdra...

CVE-2021-35069

HIGH CVSS 7.8 Feb 11, 2022

This vulnerability allows improper validation of data length from DMA buffers, leading to memory corruption in Qualcomm Snapdragon chipsets. It affects multiple Snapdragon product lines including Auto...

CVE-2021-30272

HIGH CVSS 7.3 Jan 3, 2022

A null pointer dereference vulnerability in Qualcomm Snapdragon thread cache operation handler allows attackers to cause denial of service or potentially execute arbitrary code by exploiting insuffici...

CVE-2021-30303

HIGH CVSS 7.8 Jan 3, 2022

This vulnerability allows attackers to execute arbitrary code or cause denial of service on affected Qualcomm Snapdragon devices by sending specially crafted segmented WMI commands that trigger a buff...

CVE-2021-30288

HIGH CVSS 8.4 Oct 20, 2021

This vulnerability allows attackers to trigger a stack overflow by exploiting improper length validation of TLV (Type-Length-Value) data structures in Qualcomm Snapdragon chipsets. Successful exploita...

CVE-2021-30302

HIGH CVSS 7.5 Oct 20, 2021

This vulnerability allows improper authentication of EAP WAPI EAPOL frames from unauthenticated users, potentially leading to information disclosure. It affects various Snapdragon chipsets used in com...

CVE-2021-1971

HIGH CVSS 7.5 Sep 9, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows attackers to trigger an assertion failure due to lack of physical layer state validation. It affects multiple Snapdragon product lines includi...

CVE-2021-1909

HIGH CVSS 7.3 Sep 9, 2021

CVE-2021-1909 is a buffer overflow vulnerability in Qualcomm Snapdragon trusted applications due to insufficient parameter length validation. This allows attackers to execute arbitrary code in trusted...

CVE-2021-1953

HIGH CVSS 7.5 Jul 13, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows remote attackers to trigger a reachable assertion by sending malformed Fine Timing Measurement Request (FTMR) frames. Exploitation could lead ...

CVE-2021-1938

HIGH CVSS 7.5 Jul 13, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows assertion failures due to improper verification during peer creation/deletion operations. It affects multiple Snapdragon product lines includi...

CVE-2021-1943

HIGH CVSS 7.5 Jul 13, 2021

This vulnerability allows attackers to read memory beyond allocated buffer boundaries in Qualcomm Snapdragon chipsets when parsing beacon responses. It affects devices using vulnerable Snapdragon comp...

CVE-2021-1937

HIGH CVSS 7.5 Jun 9, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows an attacker to trigger a reachable assertion while processing WLAN peer association messages, potentially causing denial of service or remote ...

CVE-2020-11235

HIGH CVSS 7.8 Jun 9, 2021

CVE-2020-11235 is a buffer overflow vulnerability in Qualcomm Snapdragon chipsets that occurs when parsing unified commands without proper input validation. Attackers could exploit this to execute arb...

CVE-2020-11241

HIGH CVSS 7.5 Jun 9, 2021

This vulnerability allows an attacker to trigger an out-of-bounds read in Qualcomm Snapdragon chipsets when processing EAPOL keys with insufficient length in NAN shared key descriptor attributes. This...

CVE-2021-1925

HIGH CVSS 7.5 May 7, 2021

This vulnerability in Qualcomm Snapdragon chipsets allows denial of service attacks through improper handling of group management action frames in wireless communication. Attackers can send specially ...