Lucene search

K
cveQualcommCVE-2022-40505
HistoryMay 02, 2023 - 6:15 a.m.

CVE-2022-40505

2023-05-0206:15:10
CWE-126
CWE-125
qualcomm
web.nvd.nist.gov
43
cve-2022-40505
information disclosure
modem
buffer over-read
dns hostname
nvd

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

37.3%

Information disclosure due to buffer over-read in Modem while parsing DNS hostname.

Affected configurations

Nvd
Node
qualcomm9205_lte_modemMatch-
AND
qualcomm9205_lte_modem_firmwareMatch-
Node
qualcomm9206_lte_modemMatch-
AND
qualcomm9206_lte_modem_firmwareMatch-
Node
qualcomm9207_lte_modemMatch-
AND
qualcomm9207_lte_modem_firmwareMatch-
Node
qualcommmdm8207Match-
AND
qualcommmdm8207_firmwareMatch-
Node
qualcommqca4004Match-
AND
qualcommqca4004_firmwareMatch-
Node
qualcommqca4010Match-
AND
qualcommqca4010_firmwareMatch-
Node
qualcommqts110_firmwareMatch-
AND
qualcommqts110Match-
Node
qualcommsnapdragon_1100_wearable_platform_firmwareMatch-
AND
qualcommsnapdragon_1100_wearable_platformMatch-
Node
qualcommsnapdragon_1200_wearable_platform_firmwareMatch-
AND
qualcommsnapdragon_1200_wearable_platformMatch-
Node
qualcommsnapdragon_wear_1300_platform_firmwareMatch-
AND
qualcommsnapdragon_wear_1300_platformMatch-
Node
qualcommsnapdragon_x5_lte_modem_firmwareMatch-
AND
qualcommsnapdragon_x5_lte_modemMatch-
Node
qualcommwcd9306_firmwareMatch-
AND
qualcommwcd9306Match-
Node
qualcommwcd9330_firmwareMatch-
AND
qualcommwcd9330Match-
VendorProductVersionCPE
qualcomm9205_lte_modem-cpe:2.3:h:qualcomm:9205_lte_modem:-:*:*:*:*:*:*:*
qualcomm9205_lte_modem_firmware-cpe:2.3:o:qualcomm:9205_lte_modem_firmware:-:*:*:*:*:*:*:*
qualcomm9206_lte_modem-cpe:2.3:h:qualcomm:9206_lte_modem:-:*:*:*:*:*:*:*
qualcomm9206_lte_modem_firmware-cpe:2.3:o:qualcomm:9206_lte_modem_firmware:-:*:*:*:*:*:*:*
qualcomm9207_lte_modem-cpe:2.3:h:qualcomm:9207_lte_modem:-:*:*:*:*:*:*:*
qualcomm9207_lte_modem_firmware-cpe:2.3:o:qualcomm:9207_lte_modem_firmware:-:*:*:*:*:*:*:*
qualcommmdm8207-cpe:2.3:h:qualcomm:mdm8207:-:*:*:*:*:*:*:*
qualcommmdm8207_firmware-cpe:2.3:o:qualcomm:mdm8207_firmware:-:*:*:*:*:*:*:*
qualcommqca4004-cpe:2.3:h:qualcomm:qca4004:-:*:*:*:*:*:*:*
qualcommqca4004_firmware-cpe:2.3:o:qualcomm:qca4004_firmware:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Snapdragon Consumer IOT",
      "Snapdragon Industrial IOT"
    ],
    "product": "Snapdragon",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "9205 LTE Modem"
      },
      {
        "status": "affected",
        "version": "9206 LTE Modem"
      },
      {
        "status": "affected",
        "version": "9207 LTE Modem"
      },
      {
        "status": "affected",
        "version": "MDM8207"
      },
      {
        "status": "affected",
        "version": "QCA4004"
      },
      {
        "status": "affected",
        "version": "QCA4010"
      },
      {
        "status": "affected",
        "version": "QTS110"
      },
      {
        "status": "affected",
        "version": "Snapdragon 1100 Wearable Platform"
      },
      {
        "status": "affected",
        "version": "Snapdragon 1200 Wearable Platform"
      },
      {
        "status": "affected",
        "version": "Snapdragon Wear 1300 Platform"
      },
      {
        "status": "affected",
        "version": "Snapdragon X5 LTE Modem"
      },
      {
        "status": "affected",
        "version": "WCD9306"
      },
      {
        "status": "affected",
        "version": "WCD9330"
      }
    ]
  }
]

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

37.3%

Related for CVE-2022-40505