Cryptographic issues in Qualcomm products - CVE-2022-25674
Published: November 7, 2022
Vulnerability identifier: #VU69018
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25674
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to an error in WLAN during the group key handshake of the WPA/WPA2 protocol. A remote attacker can perform MitM attack.
Affected software
AR8031
CSRA6620
CSRA6640
MDM9205
QCA4004
QCA4010
QCA4020
QCA4024
WCD9306
WCD9335
WCN3980
WCN3998
WCN3999
WSA8810
WSA8815
Pixel
QCS405
CSRA6620
CSRA6640
MDM9205
QCA4004
QCA4010
QCA4020
QCA4024
WCD9306
WCD9335
WCN3980
WCN3998
WCN3999
WSA8810
WSA8815
Pixel
QCS405
How to mitigate CVE-2022-25674
Install updates from vendor's website.
Pixel - update to 12L 2022-11-05