#VU74310 Buffer over-read in Qualcomm products - CVE-2022-25726
Published: April 3, 2023
Vulnerability identifier: #VU74310
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-25726
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
9205 LTE Modem
9206 LTE Modem
9207 LTE Modem
FastConnect 6900
FastConnect 7800
MDM8207
QCA4004
QTS110
Snapdragon 1100 Wearable Platform
Snapdragon 1200 Wearable Platform
Snapdragon AR2 Gen 1 Platform
Snapdragon Wear 1300 Platform
Snapdragon X5 LTE Modem
SSG2115P
SSG2125P
SXR1230P
SXR2230P
WCD9306
WCD9330
WCD9380
WCD9385
WSA8830
WSA8835
WSA8832
9205 LTE Modem
9206 LTE Modem
9207 LTE Modem
FastConnect 6900
FastConnect 7800
MDM8207
QCA4004
QTS110
Snapdragon 1100 Wearable Platform
Snapdragon 1200 Wearable Platform
Snapdragon AR2 Gen 1 Platform
Snapdragon Wear 1300 Platform
Snapdragon X5 LTE Modem
SSG2115P
SSG2125P
SXR1230P
SXR2230P
WCD9306
WCD9330
WCD9380
WCD9385
WSA8830
WSA8835
WSA8832
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a remote attacker to read and manipulate data.
The vulnerability exists due to improper input validation in MODEM. A remote attacker can read and manipulate data.
Remediation
Install security update from vendor's website.