SB2022111132 - Multiple vulnerabilities in Intel XMM 7560 Modem Software
Published: November 11, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 secuirty vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2022-26513)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker on the local network can trigger out-of-bounds write and execute arbitrary code on the target system with elevated privileges.
2) Improper Authentication (CVE-ID: CVE-2022-27874)
The vulnerability allows a local user to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. An administrator with physical access can bypass authentication process and gain elevated privileges on the system.
3) Input validation error (CVE-ID: CVE-2022-28611)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input. An administrator with physical access can pass specially crafted input to the application and gain elevated privileges.
4) Out-of-bounds read (CVE-ID: CVE-2022-26369)
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition. A remote administrator on the local network, trigger out-of-bounds read error and read contents of memory on the system.
5) Input validation error (CVE-ID: CVE-2022-28126)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A local administrator can pass specially crafted input to the application and perform a denial of service (DoS) attack.
6) Out-of-bounds read (CVE-ID: CVE-2022-26367)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition. A local administrator can trigger out-of-bounds read error and read contents of memory on the system.
7) Input validation error (CVE-ID: CVE-2022-26079)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper conditions check. A local administrator can pass specially crafted input to the application and perform a denial of service (DoS) attack.
8) Incomplete cleanup (CVE-ID: CVE-2022-27639)
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to incomplete cleanup. A remote administrator on the local network can pass specially crafted input to the application and perform a denial of service (DoS) attack.
9) Buffer overflow (CVE-ID: CVE-2022-26045)
The vulnerability allows a local user to compromsie the target system.
The vulnerability exists due to a boundary error. An administrator with physical access can trigger memory corruption and gain elevated privileges on the system.
Remediation
Install update from vendor's website.