7.5

CVE-2022-25737

Use of Uninitialized Variable in MODEM

Information disclosure in modem due to missing NULL check  while reading packets received from local network
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommMdm8207 Firmware Version-
   QualcommMdm8207 Version-
QualcommMdm9205 Firmware Version-
   QualcommMdm9205 Version-
QualcommMdm9206 Firmware Version-
   QualcommMdm9206 Version-
QualcommMdm9207 Firmware Version-
   QualcommMdm9207 Version-
QualcommQca4004 Firmware Version-
   QualcommQca4004 Version-
QualcommQts110 Firmware Version-
   QualcommQts110 Version-
QualcommWcd9306 Firmware Version-
   QualcommWcd9306 Version-
QualcommWcd9330 Firmware Version-
   QualcommWcd9330 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.532
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
product-security@qualcomm.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-457 Use of Uninitialized Variable

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.