Buffer over-read in Qualcomm products - CVE-2022-33229

 

Buffer over-read in Qualcomm products - CVE-2022-33229

Published: February 7, 2023


Vulnerability identifier: #VU71951
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33229
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read and manipulate data.

The vulnerability exists due to improper input validation in Modem. A remote attacker can read and manipulate data.


Affected software

QCA4020
WSA8815
WSA8810
WCN3999
WCN3980
WCD9335
WCD9330
WCD9306
QTS110
QCA4024
AR8031
QCA4010
QCA4004
MDM9207
MDM9205
MDM8207
CSRA6640
CSRA6620
QCS405
MDM9607
MDM9206

How to mitigate CVE-2022-33229

Install security update from vendor's website.


External References

Related Security Bulletins