Buffer overflow in Qualcomm products - CVE-2022-25727

 

Buffer overflow in Qualcomm products - CVE-2022-25727

Published: November 7, 2022


Vulnerability identifier: #VU69020
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25727
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing network traffic within the modem component. A remote attacker can send specially crafted traffic to the device, trigger memory corruption and execute arbitrary code on the target system.



Affected software

QCA4020
WSA8815
WSA8810
WCN3999
WCN3998
WCN3980
WCD9335
WCD9330
WCD9306
QCA4024
AR8031
QCA4010
QCA4004
MDM9207
MDM9205
MDM8207
CSRA6640
CSRA6620
QCS405
MDM9607
MDM9206

How to mitigate CVE-2022-25727

Install updates from vendor's website.


External References

Related Security Bulletins