Lucene search

K
cveQualcommCVE-2022-25731
HistoryApr 13, 2023 - 7:15 a.m.

CVE-2022-25731

2023-04-1307:15:11
CWE-131
CWE-125
qualcomm
web.nvd.nist.gov
43
cve-2022-25731
information disclosure
modem
buffer over-read
dns server
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

41.0%

Information disclosure in modem due to buffer over-read while processing packets from DNS server

Affected configurations

Nvd
Node
qualcommmdm9205_firmwareMatch-
AND
qualcommmdm9205Match-
Node
qualcommmdm9206_firmwareMatch-
AND
qualcommmdm9206Match-
Node
qualcommmdm9207_firmwareMatch-
AND
qualcommmdm9207Match-
Node
qualcommmdm8207_firmwareMatch-
AND
qualcommmdm8207Match-
Node
qualcommqca4004_firmwareMatch-
AND
qualcommqca4004Match-
Node
qualcommqca4010_firmwareMatch-
AND
qualcommqca4010Match-
Node
qualcommqts110_firmwareMatch-
AND
qualcommqts110Match-
Node
qualcommsnapdragon_wear_1100_firmwareMatch-
AND
qualcommsnapdragon_wear_1100Match-
Node
qualcommsnapdragon_wear_1200_firmwareMatch-
AND
qualcommsnapdragon_wear_1200Match-
Node
qualcommsnapdragon_wear_1300_firmwareMatch-
AND
qualcommsnapdragon_wear_1300Match-
Node
qualcommsnapdragon_x5_lte_modem_firmwareMatch-
AND
qualcommsnapdragon_x5_lte_modemMatch-
Node
qualcommwcd9330_firmwareMatch-
AND
qualcommwcd9330Match-
Node
qualcommwcd9306_firmwareMatch-
AND
qualcommwcd9306Match-
VendorProductVersionCPE
qualcommmdm9205_firmware-cpe:2.3:o:qualcomm:mdm9205_firmware:-:*:*:*:*:*:*:*
qualcommmdm9205-cpe:2.3:h:qualcomm:mdm9205:-:*:*:*:*:*:*:*
qualcommmdm9206_firmware-cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:*
qualcommmdm9206-cpe:2.3:h:qualcomm:mdm9206:-:*:*:*:*:*:*:*
qualcommmdm9207_firmware-cpe:2.3:o:qualcomm:mdm9207_firmware:-:*:*:*:*:*:*:*
qualcommmdm9207-cpe:2.3:h:qualcomm:mdm9207:-:*:*:*:*:*:*:*
qualcommmdm8207_firmware-cpe:2.3:o:qualcomm:mdm8207_firmware:-:*:*:*:*:*:*:*
qualcommmdm8207-cpe:2.3:h:qualcomm:mdm8207:-:*:*:*:*:*:*:*
qualcommqca4004_firmware-cpe:2.3:o:qualcomm:qca4004_firmware:-:*:*:*:*:*:*:*
qualcommqca4004-cpe:2.3:h:qualcomm:qca4004:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Snapdragon Consumer IOT",
      "Snapdragon Industrial IOT"
    ],
    "product": "Snapdragon",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "9205 LTE Modem"
      },
      {
        "status": "affected",
        "version": "9206 LTE Modem"
      },
      {
        "status": "affected",
        "version": "9207 LTE Modem"
      },
      {
        "status": "affected",
        "version": "MDM8207"
      },
      {
        "status": "affected",
        "version": "QCA4004"
      },
      {
        "status": "affected",
        "version": "QCA4010"
      },
      {
        "status": "affected",
        "version": "QTS110"
      },
      {
        "status": "affected",
        "version": "Snapdragon 1100 Wearable Platform"
      },
      {
        "status": "affected",
        "version": "Snapdragon 1200 Wearable Platform"
      },
      {
        "status": "affected",
        "version": "Snapdragon Wear 1300 Platform"
      },
      {
        "status": "affected",
        "version": "Snapdragon X5 LTE Modem"
      },
      {
        "status": "affected",
        "version": "WCD9306"
      },
      {
        "status": "affected",
        "version": "WCD9330"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

41.0%

Related for CVE-2022-25731