Reachable Assertion in Qualcomm products - CVE-2022-25702

 

Reachable Assertion in Qualcomm products - CVE-2022-25702

Published: December 6, 2022


Vulnerability identifier: #VU69959
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25702
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion within the Modem component when processing reconfiguration message. A remote attacker can send specially crafted data to the device and perform a denial of service (DoS) attack.

Affected software

SM7250P
WCN3610
WCD9385
WCD9380
WCD9375
WCD9370
WCD9341
WCD9340
WCD9326
SM7315
WCN3615
SM4375
SDXR2 5G
SDX65
SDX55M
SDX50M
SDA429W
WCN6850
WSA8835
WSA8830
WSA8815
WSA8810
WCN7851
WCN7850
WCN6856
WCN6855
WCN6851
SD870
WCN6750
WCN6740
WCN3998
WCN3991
WCN3988
WCN3980
WCN3680B
WCN3660B
WCN3620
QCA8337
QCA8081
QCA6436
QCA6431
QCA6426
QCA6421
QCA6391
QCA6390
QCN6024
MSM8608
MSM8209
MSM8208
MSM8108
FSM10055
AR8035
AQT1000
APQ8037
SD480
SD865 5G
SD780G
SD768G
SD765G
SD765
SD750G
SD695
SD690 5G
SD439
SD429
SD 8 Gen1 5G
SA515M
QCX315
QCN9024
SDX55
SDM429W
SD888
MSM8917
MSM8937
APQ8017
SD855
APQ8009
SD210
SD205
Google Android

How to mitigate CVE-2022-25702

Install updates from vendor's website.

Google Android - addressed in versions 10 2022-12-05, 11 2022-12-05, 12L 2022-12-05, 12 2022-12-05, 13 2022-12-05

External References

Related Security Bulletins