9.8

CVE-2022-25727

Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

Data is provided by the National Vulnerability Database (NVD)
QualcommAr8031 Firmware Version-
   QualcommAr8031 Version-
QualcommCsra6620 Firmware Version-
   QualcommCsra6620 Version-
QualcommCsra6640 Firmware Version-
   QualcommCsra6640 Version-
QualcommMdm8207 Firmware Version-
   QualcommMdm8207 Version-
QualcommMdm9205 Firmware Version-
   QualcommMdm9205 Version-
QualcommMdm9206 Firmware Version-
   QualcommMdm9206 Version-
QualcommMdm9207 Firmware Version-
   QualcommMdm9207 Version-
QualcommMdm9607 Firmware Version-
   QualcommMdm9607 Version-
QualcommQca4004 Firmware Version-
   QualcommQca4004 Version-
QualcommQca4010 Firmware Version-
   QualcommQca4010 Version-
QualcommQca4020 Firmware Version-
   QualcommQca4020 Version-
QualcommQca4024 Firmware Version-
   QualcommQca4024 Version-
QualcommQcs405 Firmware Version-
   QualcommQcs405 Version-
QualcommWcd9306 Firmware Version-
   QualcommWcd9306 Version-
QualcommWcd9330 Firmware Version-
   QualcommWcd9330 Version-
QualcommWcd9335 Firmware Version-
   QualcommWcd9335 Version-
QualcommWcn3980 Firmware Version-
   QualcommWcn3980 Version-
QualcommWcn3998 Firmware Version-
   QualcommWcn3998 Version-
QualcommWcn3999 Firmware Version-
   QualcommWcn3999 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.484
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
product-security@qualcomm.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1284 Improper Validation of Specified Quantity in Input

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.