Vulnerability Name:

CVE-2022-25651 (CCN-229074)

Assigned:2022-06-06
Published:2022-06-06
Updated:2022-06-22
Summary:Memory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-190
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2022-25651

Source: CCN
Type: Qualcomm Web site
June 2022 Security Bulletin

Source: XF
Type: UNKNOWN
qualcomm-cve202225651-code-exec(229074)

Source: CONFIRM
Type: Vendor Advisory
https://www.qualcomm.com/company/product-security/bulletins/june-2022-bulletin

Vulnerable Configuration:Configuration 1:
  • cpe:/o:qualcomm:apq8009_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:apq8009:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:qualcomm:apq8017_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:apq8017:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:qualcomm:apq8053_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:apq8053:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:qualcomm:apq8096au_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:apq8096au:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:qualcomm:ar8031_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:ar8031:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:qualcomm:csra6620_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:csra6620:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:qualcomm:csra6640_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:csra6640:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:qualcomm:csrb31024_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:csrb31024:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:qualcomm:mdm9150_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:mdm9150:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:qualcomm:mdm9250_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:mdm9250:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:mdm9607:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:qualcomm:mdm9626_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:mdm9626:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:qualcomm:mdm9628_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:mdm9628:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:qualcomm:mdm9640_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:mdm9640:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:mdm9650:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:qualcomm:qca4020_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca4020:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6174a:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:qualcomm:qca6564a_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6564a:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:qualcomm:qca6564au_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6564au:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6574:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6574a:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6574au:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:qualcomm:qca6584_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6584:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:qualcomm:qca6595_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6595:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6595au:-:*:*:*:*:*:*:*

  • Configuration 26:
  • cpe:/o:qualcomm:qca6696_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6696:-:*:*:*:*:*:*:*

  • Configuration 27:
  • cpe:/o:qualcomm:qca9367_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca9367:-:*:*:*:*:*:*:*

  • Configuration 28:
  • cpe:/o:qualcomm:qca9377_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca9377:-:*:*:*:*:*:*:*

  • Configuration 29:
  • cpe:/o:qualcomm:qca9379_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca9379:-:*:*:*:*:*:*:*

  • Configuration 30:
  • cpe:/o:qualcomm:qcs405_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qcs405:-:*:*:*:*:*:*:*

  • Configuration 31:
  • cpe:/o:qualcomm:sa415m_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sa415m:-:*:*:*:*:*:*:*

  • Configuration 32:
  • cpe:/o:qualcomm:sa515m_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sa515m:-:*:*:*:*:*:*:*

  • Configuration 33:
  • cpe:/o:qualcomm:sa6155_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sa6155:-:*:*:*:*:*:*:*

  • Configuration 34:
  • cpe:/o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sa6155p:-:*:*:*:*:*:*:*

  • Configuration 35:
  • cpe:/o:qualcomm:sa8155_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sa8155:-:*:*:*:*:*:*:*

  • Configuration 36:
  • cpe:/o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sa8155p:-:*:*:*:*:*:*:*

  • Configuration 37:
  • cpe:/o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sa8195p:-:*:*:*:*:*:*:*

  • Configuration 38:
  • cpe:/o:qualcomm:sd820_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd820:-:*:*:*:*:*:*:*

  • Configuration 39:
  • cpe:/o:qualcomm:sdx20_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sdx20:-:*:*:*:*:*:*:*

  • Configuration 40:
  • cpe:/o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sdx55:-:*:*:*:*:*:*:*

  • Configuration 41:
  • cpe:/o:qualcomm:wcd9326_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcd9326:-:*:*:*:*:*:*:*

  • Configuration 42:
  • cpe:/o:qualcomm:wcd9335_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcd9335:-:*:*:*:*:*:*:*

  • Configuration 43:
  • cpe:/o:qualcomm:wcd9360_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcd9360:-:*:*:*:*:*:*:*

  • Configuration 44:
  • cpe:/o:qualcomm:wcn3610_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3610:-:*:*:*:*:*:*:*

  • Configuration 45:
  • cpe:/o:qualcomm:wcn3615_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3615:-:*:*:*:*:*:*:*

  • Configuration 46:
  • cpe:/o:qualcomm:wcn3660b_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3660b:-:*:*:*:*:*:*:*

  • Configuration 47:
  • cpe:/o:qualcomm:wcn3680b_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3680b:-:*:*:*:*:*:*:*

  • Configuration 48:
  • cpe:/o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3980:-:*:*:*:*:*:*:*

  • Configuration 49:
  • cpe:/o:qualcomm:wcn3998_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3998:-:*:*:*:*:*:*:*

  • Configuration 50:
  • cpe:/o:qualcomm:wcn3999_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3999:-:*:*:*:*:*:*:*

  • Configuration 51:
  • cpe:/o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wsa8810:-:*:*:*:*:*:*:*

  • Configuration 52:
  • cpe:/o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wsa8815:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:qualcomm:snapdragon_mobile:-:*:*:*:*:*:*:*
  • OR cpe:/h:qualcomm:snapdragon_auto:-:*:*:*:*:*:*:*
  • OR cpe:/h:qualcomm:snapdragon_consumer_internet_of_things:-:*:*:*:*:*:*:*
  • OR cpe:/h:qualcomm:snapdragon_industrial_internet_of_things:-:*:*:*:*:*:*:*
  • OR cpe:/h:qualcomm:snapdragon_voice_&_music:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    qualcomm apq8009 firmware -
    qualcomm apq8009 -
    qualcomm apq8017 firmware -
    qualcomm apq8017 -
    qualcomm apq8053 firmware -
    qualcomm apq8053 -
    qualcomm apq8096au firmware -
    qualcomm apq8096au -
    qualcomm ar8031 firmware -
    qualcomm ar8031 -
    qualcomm csra6620 firmware -
    qualcomm csra6620 -
    qualcomm csra6640 firmware -
    qualcomm csra6640 -
    qualcomm csrb31024 firmware -
    qualcomm csrb31024 -
    qualcomm mdm9150 firmware -
    qualcomm mdm9150 -
    qualcomm mdm9250 firmware -
    qualcomm mdm9250 -
    qualcomm mdm9607 firmware -
    qualcomm mdm9607 -
    qualcomm mdm9626 firmware -
    qualcomm mdm9626 -
    qualcomm mdm9628 firmware -
    qualcomm mdm9628 -
    qualcomm mdm9640 firmware -
    qualcomm mdm9640 -
    qualcomm mdm9650 firmware -
    qualcomm mdm9650 -
    qualcomm qca4020 firmware -
    qualcomm qca4020 -
    qualcomm qca6174a firmware -
    qualcomm qca6174a -
    qualcomm qca6564a firmware -
    qualcomm qca6564a -
    qualcomm qca6564au firmware -
    qualcomm qca6564au -
    qualcomm qca6574 firmware -
    qualcomm qca6574 -
    qualcomm qca6574a firmware -
    qualcomm qca6574a -
    qualcomm qca6574au firmware -
    qualcomm qca6574au -
    qualcomm qca6584 firmware -
    qualcomm qca6584 -
    qualcomm qca6595 firmware -
    qualcomm qca6595 -
    qualcomm qca6595au firmware -
    qualcomm qca6595au -
    qualcomm qca6696 firmware -
    qualcomm qca6696 -
    qualcomm qca9367 firmware -
    qualcomm qca9367 -
    qualcomm qca9377 firmware -
    qualcomm qca9377 -
    qualcomm qca9379 firmware -
    qualcomm qca9379 -
    qualcomm qcs405 firmware -
    qualcomm qcs405 -
    qualcomm sa415m firmware -
    qualcomm sa415m -
    qualcomm sa515m firmware -
    qualcomm sa515m -
    qualcomm sa6155 firmware -
    qualcomm sa6155 -
    qualcomm sa6155p firmware -
    qualcomm sa6155p -
    qualcomm sa8155 firmware -
    qualcomm sa8155 -
    qualcomm sa8155p firmware -
    qualcomm sa8155p -
    qualcomm sa8195p firmware -
    qualcomm sa8195p -
    qualcomm sd820 firmware -
    qualcomm sd820 -
    qualcomm sdx20 firmware -
    qualcomm sdx20 -
    qualcomm sdx55 firmware -
    qualcomm sdx55 -
    qualcomm wcd9326 firmware -
    qualcomm wcd9326 -
    qualcomm wcd9335 firmware -
    qualcomm wcd9335 -
    qualcomm wcd9360 firmware -
    qualcomm wcd9360 -
    qualcomm wcn3610 firmware -
    qualcomm wcn3610 -
    qualcomm wcn3615 firmware -
    qualcomm wcn3615 -
    qualcomm wcn3660b firmware -
    qualcomm wcn3660b -
    qualcomm wcn3680b firmware -
    qualcomm wcn3680b -
    qualcomm wcn3980 firmware -
    qualcomm wcn3980 -
    qualcomm wcn3998 firmware -
    qualcomm wcn3998 -
    qualcomm wcn3999 firmware -
    qualcomm wcn3999 -
    qualcomm wsa8810 firmware -
    qualcomm wsa8810 -
    qualcomm wsa8815 firmware -
    qualcomm wsa8815 -
    qualcomm snapdragon mobile -
    qualcomm snapdragon auto -
    qualcomm snapdragon consumer internet of things -
    qualcomm snapdragon industrial internet of things -
    qualcomm snapdragon voice & music -