6.7

CVE-2022-25654

Memory corruption in kernel due to improper input validation while processing ION commands in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

Data is provided by the National Vulnerability Database (NVD)
QualcommApq8096au Firmware Version-
   QualcommApq8096au Version-
QualcommMdm9650 Firmware Version-
   QualcommMdm9650 Version-
QualcommQca6174a Firmware Version-
   QualcommQca6174a Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQcs603 Firmware Version-
   QualcommQcs603 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommQualcomm215 Firmware Version-
   QualcommQualcomm215 Version-
QualcommSd429 Firmware Version-
   QualcommSd429 Version-
QualcommSd820 Firmware Version-
   QualcommSd820 Version-
QualcommSdm429w Firmware Version-
   QualcommSdm429w Version-
QualcommWcd9326 Firmware Version-
   QualcommWcd9326 Version-
QualcommWcd9335 Firmware Version-
   QualcommWcd9335 Version-
QualcommWcd9341 Firmware Version-
   QualcommWcd9341 Version-
QualcommWcn3615 Firmware Version-
   QualcommWcn3615 Version-
QualcommWcn3620 Firmware Version-
   QualcommWcn3620 Version-
QualcommWcn3660b Firmware Version-
   QualcommWcn3660b Version-
QualcommWcn3680 Firmware Version-
   QualcommWcn3680 Version-
QualcommWcn3980 Firmware Version-
   QualcommWcn3980 Version-
QualcommWcn3990 Firmware Version-
   QualcommWcn3990 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.296
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
product-security@qualcomm.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.