Buffer overflow in Qualcomm products - CVE-2022-25678

 

Buffer overflow in Qualcomm products - CVE-2022-25678

Published: April 3, 2023


Vulnerability identifier: #VU74301
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25678
CWE-ID: CWE-120
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in MODEM. A remote attacker can execute arbitrary code.


Affected software

9205 LTE Modem
9206 LTE Modem
9207 LTE Modem
MDM8207
QCA4004
QTS110
Snapdragon 1100 Wearable Platform
Snapdragon 1200 Wearable Platform
Snapdragon Wear 1300 Platform
Snapdragon X5 LTE Modem
WCD9306
WCD9330

How to mitigate CVE-2022-25678

Install security update from vendor's website.


External References

Related Security Bulletins