9.8
CVE-2022-25745
- EPSS 0.32%
- Veröffentlicht 13.04.2023 07:15:13
- Zuletzt bearbeitet 21.11.2024 06:52:53
- Quelle product-security@qualcomm.com
- CVE-Watchlists
- Unerledigt
Always Incorrect Control Flow Implementation in MODEM
Memory corruption in modem due to improper input validation while handling the incoming CoAP message
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Mdm9205 Firmware Version-
Qualcomm ≫ Qca4004 Firmware Version-
Qualcomm ≫ Qts110 Firmware Version-
Qualcomm ≫ Snapdragon Wear 1300 Firmware Version-
Qualcomm ≫ Wcd9306 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.552 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| product-security@qualcomm.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-670 Always-Incorrect Control Flow Implementation
The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.