#VU71939 Improper Input Validation in Qualcomm products - CVE-2022-25729

 

#VU71939 Improper Input Validation in Qualcomm products - CVE-2022-25729

Published: February 7, 2023


Vulnerability identifier: #VU71939
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-25729
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AR8031
CSRA6620
CSRA6640
MDM9205
QCA4004
QCA4020
QCA4024
QTS110
SSG2115P
SSG2125P
SXR1230P
SXR2230P
WCD9306
WCD9335
WCD9380
WCD9385
WCN3980
WCN3998
WCN3999
WCN6855
WCN6856
WCN7850
WCN7851
WSA8810
WSA8815
WSA8830
WSA8835
MDM9206
QCS405
WSA8832
Software vendor:
Qualcomm

Description

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in MODEM. A remote attacker can execute arbitrary code.


Remediation

Install security update from vendor's website.

External links