Qca7520 Firmware
Vendor:
First CVE: Feb 22, 2021 · Active for 5 years
19
Total CVEs
More Total CVEs than 95% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 71% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Qca7520 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 22, 2021
5 years ago
Most Recent CVE
Sep 5, 2023
1,057 days ago
CVE Severity & Scoring
Qca7520 Firmware19 CVEs
16%
68%
16%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local12 (63.2%)
Network7 (36.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low12 (63.2%)
High0 (0.0%)
None7 (36.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1976CRITICAL A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | Sep 17, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-1972CRITICAL Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snap | Sep 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2022-33265CRITICAL Memory corruption due to information exposure in Powerline Communication Firmware while sending different MMEs from a single, unassociated device. | Jan 9, 2023 | 9.8 | 29 | NO | NO |
CVE-2020-11301HIGH Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect | Sep 8, 2021 | 7.5 | 29 | NO | NO |
CVE-2021-30303HIGH Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consu | Jan 3, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-1909HIGH Buffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electr | Sep 9, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-1887HIGH An assertion can be reached in the WLAN subsystem while using the Wi-Fi Fine Timing Measurement protocol in Snapdragon Wired Infrastructure and Networking | Jul 13, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-11256HIGH Memory corruption due to lack of check of validation of pointer to buffer passed to trustzone in Snapdragon Wired Infrastructure and Networking | Jun 9, 2021 | 8.8 | 23 | NO | NO |
CVE-2023-28565HIGH Memory corruption in WLAN HAL while handling command streams through WMI interfaces. | Sep 5, 2023 | 7.8 | 22 | NO | NO |
CVE-2020-11259HIGH Memory corruption due to lack of validation of pointer arguments passed to Trustzone BSP in Snapdragon Wired Infrastructure and Networking | Jun 9, 2021 | 8.8 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Qca7520 Firmware
Top CWEs
Versions
No cataloged versions.