Improper Input Validation in Qualcomm products - CVE-2022-25729

 

Improper Input Validation in Qualcomm products - CVE-2022-25729

Published: February 7, 2023


Vulnerability identifier: #VU71939
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25729
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in MODEM. A remote attacker can execute arbitrary code.


Affected software

WCD9335
WSA8835
WSA8830
WSA8815
WSA8810
WCN7851
WCN7850
WCN6856
WCN6855
WCN3999
WCN3998
WCN3980
WCD9385
WCD9380
AR8031
WCD9306
SXR2230P
SXR1230P
SSG2125P
SSG2115P
QTS110
QCA4024
QCA4020
QCA4004
MDM9205
CSRA6640
CSRA6620
WSA8832
QCS405
MDM9206

How to mitigate CVE-2022-25729

Install security update from vendor's website.


External References

Related Security Bulletins