Loop with Unreachable Exit Condition ('Infinite Loop') in Qualcomm products - CVE-2022-25734

 

Loop with Unreachable Exit Condition ('Infinite Loop') in Qualcomm products - CVE-2022-25734

Published: February 7, 2023


Vulnerability identifier: #VU71946
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25734
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation in MODEM. A remote attacker can perform a denial of service (DoS) attack.


Affected software

WCN6855
WCD9306
WCD9330
WCD9335
WCD9380
WCD9385
WCN3980
WCN3998
WCN3999
SXR2230P
WCN6856
WCN7850
WCN7851
WSA8810
WSA8815
WSA8830
WSA8835
QCA4010
CSRA6620
CSRA6640
MDM8207
MDM9205
MDM9207
QCA4004
AR8031
QCA4020
QCA4024
QTS110
SSG2115P
SSG2125P
SXR1230P
WSA8832
MDM9206
MDM9607
QCS405

How to mitigate CVE-2022-25734

Install security update from vendor's website.


External References

Related Security Bulletins