Lucene search

K
vulnrichmentQualcommVULNRICHMENT:CVE-2022-25739
HistoryApr 04, 2023 - 4:46 a.m.

CVE-2022-25739 Null Point Dereference in MODEM

2023-04-0404:46:17
CWE-476
qualcomm
github.com
7
cve-2022-25739
denial of service
ipv6 packet received

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

37.5%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:9205_lte_modem_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "9205_lte_modem_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:9206_lte_modem_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "9206_lte_modem_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:9207_lte_modem_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "9207_lte_modem_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:fastconnect_6900_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "fastconnect_6900_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:fastconnect_7800_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "fastconnect_7800_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:mdm8207_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "mdm8207_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qca4004_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qca4004_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:qts110_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "qts110_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:snapdragon_1100_wearable_platform_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "snapdragon_1100_wearable_platform_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:snapdragon_1200_wearable_platform_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "snapdragon_1200_wearable_platform_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:snapdragon_ar2_gen_1_platform_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "snapdragon_ar2_gen_1_platform_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:snapdragon_wear_1300_platform_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "snapdragon_wear_1300_platform_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:snapdragon_x5_lte_modem_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "snapdragon_x5_lte_modem_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:ssg2115p_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "ssg2115p_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:ssg2125p_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "ssg2125p_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:sxr1230p_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "sxr1230p_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:sxr2230p_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "sxr2230p_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9306_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9306_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9330_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9330_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9380_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wcd9385_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8830_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8832_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8832_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*"
    ],
    "vendor": "qualcomm",
    "product": "wsa8835_firmware",
    "versions": [
      {
        "status": "affected",
        "version": "*"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

37.5%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

Related for VULNRICHMENT:CVE-2022-25739