Reachable Assertion in Qualcomm products - CVE-2022-25689
Published: December 6, 2022
Vulnerability identifier: #VU69954
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25689
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion within the Modem component. A remote attacker can send specially crafted data to the device and perform a denial of service (DoS) attack.Affected software
AR8035
QCA8081
QCA8337
QCN6024
QCN9024
SDX65
WCD9380
WCN6855
WCN6856
Google Android
QCA8081
QCA8337
QCN6024
QCN9024
SDX65
WCD9380
WCN6855
WCN6856
Google Android
How to mitigate CVE-2022-25689
Install updates from vendor's website.
Google Android - addressed in versions 10 2022-12-05, 11 2022-12-05, 12L 2022-12-05, 12 2022-12-05, 13 2022-12-05