Buffer over-read in Qualcomm products - CVE-2022-25730

 

Buffer over-read in Qualcomm products - CVE-2022-25730

Published: April 3, 2023


Vulnerability identifier: #VU74311
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25730
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read and manipulate data.

The vulnerability exists due to improper input validation in MODEM. A remote attacker can read and manipulate data.


Affected software

Snapdragon Wear 1300 Platform
WSA8835
WSA8830
WCD9385
WCD9380
WCD9330
WCD9306
SXR2230P
SXR1230P
SSG2125P
SSG2115P
Snapdragon X5 LTE Modem
9205 LTE Modem
Snapdragon AR2 Gen 1 Platform
Snapdragon 1200 Wearable Platform
Snapdragon 1100 Wearable Platform
QTS110
QCA4010
QCA4004
MDM8207
FastConnect 7800
FastConnect 6900
9207 LTE Modem
9206 LTE Modem
WSA8832

How to mitigate CVE-2022-25730

Install security update from vendor's website.


External References

Related Security Bulletins