#VU74321 Time-of-check Time-of-use (TOCTOU) Race Condition in Qualcomm products - CVE-2022-33270
Published: April 3, 2023
Vulnerability identifier: #VU74321
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-33270
CWE-ID: CWE-367
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
AR8035
FastConnect 6200
FastConnect 6700
FastConnect 6900
FastConnect 7800
QCA6391
QCA6595AU
QCA6696
QCA6698AQ
QCA8081
QCA8337
QCM6490
QCN6024
QCN9024
QCS6490
SD778G
SDX57M
SM7325P
Snapdragon 4 Gen 1 Mobile Platform
Snapdragon 480 5G Mobile Platform
Snapdragon 480+ 5G Mobile Platform (SM4350-AC)
Snapdragon 695 5G Mobile Platform
Snapdragon 778G 5G Mobile Platform
Snapdragon 778G+ 5G Mobile Platform (SM7325-AE)
Snapdragon 782G Mobile Platform (SM7325-AF)
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 888 5G Mobile Platform
Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
Snapdragon Auto 5G Modem-RF
Snapdragon X65 5G Modem-RF System
Snapdragon X70 Modem-RF System
WCD9370
WCD9375
WCD9380
WCD9385
WCN3988
WSA8810
WSA8815
WSA8830
WSA8835
AR8035
FastConnect 6200
FastConnect 6700
FastConnect 6900
FastConnect 7800
QCA6391
QCA6595AU
QCA6696
QCA6698AQ
QCA8081
QCA8337
QCM6490
QCN6024
QCN9024
QCS6490
SD778G
SDX57M
SM7325P
Snapdragon 4 Gen 1 Mobile Platform
Snapdragon 480 5G Mobile Platform
Snapdragon 480+ 5G Mobile Platform (SM4350-AC)
Snapdragon 695 5G Mobile Platform
Snapdragon 778G 5G Mobile Platform
Snapdragon 778G+ 5G Mobile Platform (SM7325-AE)
Snapdragon 782G Mobile Platform (SM7325-AF)
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 888 5G Mobile Platform
Snapdragon 888+ 5G Mobile Platform (SM8350-AC)
Snapdragon Auto 5G Modem-RF
Snapdragon X65 5G Modem-RF System
Snapdragon X70 Modem-RF System
WCD9370
WCD9375
WCD9380
WCD9385
WCN3988
WSA8810
WSA8815
WSA8830
WSA8835
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation in Modem. A remote attacker can perform a denial of service (DoS) attack.
Remediation
Install security update from vendor's website.