Buffer overflow in Qualcomm products - CVE-2022-25708

 

Buffer overflow in Qualcomm products - CVE-2022-25708

Published: September 6, 2022


Vulnerability identifier: #VU67043
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25708
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in WLAN Firmware when processing keys. A remote attacker on the local network can send specially crafted input to the affected device, trigger memory corruption and execute arbitrary code on the target system.


Affected software

WCN6850
WSA8835
WSA8830
WCN7851
WCN7850
WCN6856
WCN6855
WCN6851
SD 8 Gen1 5G
WCN6750
WCD9385
WCD9380
WCD9375
WCD9370
SD888 5G
WSA8832
SM7450
Google Android

How to mitigate CVE-2022-25708

Install updates from vendor's website.

Google Android - addressed in versions 10 2022-09-05, 11 2022-09-05, 12L 2022-09-05, 12 2022-09-05, 13 2022-09-05

External References

Related Security Bulletins