#VU71951 Buffer over-read in Qualcomm products - CVE-2022-33229
Published: February 7, 2023
Vulnerability identifier: #VU71951
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-33229
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
AR8031
CSRA6620
CSRA6640
MDM8207
MDM9205
MDM9207
QCA4004
QCA4010
QCA4020
QCA4024
QTS110
WCD9306
WCD9330
WCD9335
WCN3980
WCN3999
WSA8810
WSA8815
MDM9206
MDM9607
QCS405
AR8031
CSRA6620
CSRA6640
MDM8207
MDM9205
MDM9207
QCA4004
QCA4010
QCA4020
QCA4024
QTS110
WCD9306
WCD9330
WCD9335
WCN3980
WCN3999
WSA8810
WSA8815
MDM9206
MDM9607
QCS405
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a remote attacker to read and manipulate data.
The vulnerability exists due to improper input validation in Modem. A remote attacker can read and manipulate data.
Remediation
Install security update from vendor's website.