Buffer over-read in Qualcomm products - CVE-2022-25732
Published: February 7, 2023
Vulnerability identifier: #VU71944
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25732
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to read and manipulate data.
The vulnerability exists due to improper input validation in MODEM. A remote attacker can read and manipulate data.
Affected software
WCN6856
WCD9306
WCD9330
WCD9335
WCD9380
WCD9385
WCN3980
WCN3999
WCN6855
SXR2230P
WCN7850
WCN7851
WSA8810
WSA8815
WSA8830
WSA8835
AR8031
SXR1230P
SSG2125P
SSG2115P
QTS110
QCA4024
QCA4020
QCA4004
MDM9207
MDM9205
MDM8207
CSRA6640
CSRA6620
WSA8832
QCS405
MDM9607
MDM9206
WCD9306
WCD9330
WCD9335
WCD9380
WCD9385
WCN3980
WCN3999
WCN6855
SXR2230P
WCN7850
WCN7851
WSA8810
WSA8815
WSA8830
WSA8835
AR8031
SXR1230P
SSG2125P
SSG2115P
QTS110
QCA4024
QCA4020
QCA4004
MDM9207
MDM9205
MDM8207
CSRA6640
CSRA6620
WSA8832
QCS405
MDM9607
MDM9206
How to mitigate CVE-2022-25732
Install security update from vendor's website.