#VU75617 Buffer over-read in Qualcomm products - CVE-2022-40505

 

#VU75617 Buffer over-read in Qualcomm products - CVE-2022-40505

Published: May 1, 2023


Vulnerability identifier: #VU75617
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-40505
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
9205 LTE Modem
9206 LTE Modem
9207 LTE Modem
MDM8207
QCA4004
QCA4010
QTS110
Snapdragon 1100 Wearable Platform
Snapdragon 1200 Wearable Platform
Snapdragon Wear 1300 Platform
Snapdragon X5 LTE Modem
WCD9306
WCD9330
Software vendor:
Qualcomm

Description

The vulnerability allows a remote attacker to read and manipulate data.

The vulnerability exists due to improper input validation in Modem. A remote attacker can read and manipulate data.


Remediation

Install security update from vendor's website.

External links