CRITICAL · 9.8

CVE-2022-25708

Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile

Vulnerability Description

Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QualcommSd 8 Gen1 5G Firmware-
QualcommSm8475-
QualcommSd888 5G Firmware-
QualcommSd888 5G-
QualcommSm7450 Firmware-
QualcommSm7450-
QualcommWcd9370 Firmware-
QualcommWcd9370-
QualcommWcd9375 Firmware-
QualcommWcd9375-
QualcommWcd9380 Firmware-
QualcommWcd9380-
QualcommWcd9385 Firmware-
QualcommWcd9385-
QualcommWcn6750 Firmware-
QualcommWcn6750-
QualcommWcn6850 Firmware-
QualcommWcn6850-
QualcommWcn6851 Firmware-
QualcommWcn6851-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-25708?

CVE-2022-25708 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile

How severe is CVE-2022-25708?

CVE-2022-25708 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-25708?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Sd 8 Gen1 5G Firmware, Qualcomm Sm8475, Qualcomm Sd888 5G Firmware, Qualcomm Sd888 5G, Qualcomm Sm7450 Firmware.