Information exposure in Qualcomm products - CVE-2022-40525
Published: June 5, 2023
Vulnerability identifier: #VU76863
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40525
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to sensitive information.
The vulnerability exists due to improper input validation in Linux Networking Firmware. A local application can gain access to sensitive information.
Affected software
QCA8386
QCN9274
QCN9074
QCN9072
QCN9070
QCN9024
QCN9022
QCN9000
QCN6024
QCN6023
QCN5152
QCN5122
QCN5121
QCN5052
QCN5022
QCN5021
CSR8811
QCA8085
QCA8084
QCA8082
QCA8081
QCA8075
QCA8072
QCA4024
IPQ9574
IPQ9008
IPQ6028
IPQ6018
IPQ6010
IPQ6005
IPQ6000
QCN9274
QCN9074
QCN9072
QCN9070
QCN9024
QCN9022
QCN9000
QCN6024
QCN6023
QCN5152
QCN5122
QCN5121
QCN5052
QCN5022
QCN5021
CSR8811
QCA8085
QCA8084
QCA8082
QCA8081
QCA8075
QCA8072
QCA4024
IPQ9574
IPQ9008
IPQ6028
IPQ6018
IPQ6010
IPQ6005
IPQ6000
How to mitigate CVE-2022-40525
Install security update from vendor's website.