7.8

CVE-2022-33226

Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications.

Data is provided by the National Vulnerability Database (NVD)
QualcommAqt1000 Firmware Version-
   QualcommAqt1000 Version-
QualcommWcn3991 Firmware Version-
   QualcommWcn3991 Version-
QualcommWcn3998 Firmware Version-
   QualcommWcn3998 Version-
QualcommWcn685x-5 Firmware Version-
   QualcommWcn685x-5 Version-
QualcommWcn685x-1 Firmware Version-
   QualcommWcn685x-1 Version-
QualcommWcn785x-1 Firmware Version-
   QualcommWcn785x-1 Version-
QualcommWcn785x-5 Firmware Version-
   QualcommWcn785x-5 Version-
QualcommQam8255p Firmware Version-
   QualcommQam8255p Version-
QualcommQca6420 Firmware Version-
   QualcommQca6420 Version-
QualcommQca6430 Firmware Version-
   QualcommQca6430 Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca6595au Firmware Version-
   QualcommQca6595au Version-
QualcommQca6698aq Firmware Version-
   QualcommQca6698aq Version-
QualcommQca6797aq Firmware Version-
   QualcommQca6797aq Version-
QualcommSa8255p Firmware Version-
   QualcommSa8255p Version-
QualcommSd855 Firmware Version-
   QualcommSd855 Version-
QualcommSm8450 Firmware Version-
   QualcommSm8450 Version-
QualcommSm8150 Firmware Version-
   QualcommSm8150 Version-
QualcommSm8150-ac Firmware Version-
   QualcommSm8150-ac Version-
QualcommSm8350 Firmware Version-
   QualcommSm8350 Version-
QualcommSm8350-ac Firmware Version-
   QualcommSm8350-ac Version-
QualcommWcd9341 Firmware Version-
   QualcommWcd9341 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcn3610 Firmware Version-
   QualcommWcn3610 Version-
QualcommWcn3660b Firmware Version-
   QualcommWcn3660b Version-
QualcommWcn3680b Firmware Version-
   QualcommWcn3680b Version-
QualcommWcn3980 Firmware Version-
   QualcommWcn3980 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.069
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
product-security@qualcomm.com 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.