Vulnerability Description
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Aqt1000 Firmware | - |
| Qualcomm | Aqt1000 | - |
| Qualcomm | Ar8035 Firmware | - |
| Qualcomm | Ar8035 | - |
| Qualcomm | Csra6620 Firmware | - |
| Qualcomm | Csra6620 | - |
| Qualcomm | Csra6640 Firmware | - |
| Qualcomm | Csra6640 | - |
| Qualcomm | Qam8295P Firmware | - |
| Qualcomm | Qam8295P | - |
| Qualcomm | Qca6390 Firmware | - |
| Qualcomm | Qca6390 | - |
| Qualcomm | Qca6391 Firmware | - |
| Qualcomm | Qca6391 | - |
| Qualcomm | Qca6420 Firmware | - |
| Qualcomm | Qca6420 | - |
| Qualcomm | Qca6421 Firmware | - |
| Qualcomm | Qca6421 | - |
| Qualcomm | Qca6426 Firmware | - |
| Qualcomm | Qca6426 | - |
Related Weaknesses (CWE)
References
- https://www.qualcomm.com/company/product-security/bulletins/march-2023-bulletinVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/march-2023-bulletinVendor Advisory
FAQ
What is CVE-2022-33278?
CVE-2022-33278 is a vulnerability with a CVSS score of 7.8 (HIGH). Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
How severe is CVE-2022-33278?
CVE-2022-33278 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-33278?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Aqt1000 Firmware, Qualcomm Aqt1000, Qualcomm Ar8035 Firmware, Qualcomm Ar8035, Qualcomm Csra6620 Firmware.