9.8

CVE-2022-33211

Improper Input Validation in MODEM

memory corruption in modem due to improper check while calculating size of serialized CoAP message
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Mdm8207 Firmware Version -
   Qualcomm ≫ Mdm8207 Version -
Qualcomm ≫ Mdm9205 Firmware Version -
   Qualcomm ≫ Mdm9205 Version -
Qualcomm ≫ Mdm9206 Firmware Version -
   Qualcomm ≫ Mdm9206 Version -
Qualcomm ≫ Mdm9207 Firmware Version -
   Qualcomm ≫ Mdm9207 Version -
Qualcomm ≫ Qca4004 Firmware Version -
   Qualcomm ≫ Qca4004 Version -
Qualcomm ≫ Qts110 Firmware Version -
   Qualcomm ≫ Qts110 Version -
Qualcomm ≫ Wcd9306 Firmware Version -
   Qualcomm ≫ Wcd9306 Version -
Qualcomm ≫ Wcd9330 Firmware Version -
   Qualcomm ≫ Wcd9330 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.332
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Qualcomm 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-131 Incorrect Calculation of Buffer Size

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.qualcomm.com/company/product-security/bulletins/april-2023-bulletin
Vendor Advisory