Vulnerability Name:

CVE-2022-25663 (CCN-238508)

Assigned:2022-10-03
Published:2022-10-03
Updated:2022-10-21
Summary:Possible buffer overflow due to lack of buffer length check during management frame Rx handling lead to denial of service in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2022-25663

Source: CCN
Type: Qualcomm Web site
October 2022 Security Bulletin

Source: XF
Type: UNKNOWN
qualcomm-cve202225663-dos(238508)

Source: CONFIRM
Type: Vendor Advisory
https://www.qualcomm.com/company/product-security/bulletins/october-2022-bulletin

Vulnerable Configuration:Configuration 1:
  • cpe:/o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:aqt1000:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:qualcomm:qca1062_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca1062:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:qualcomm:qca1064_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca1064:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:qualcomm:qca2062_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca2062:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:qualcomm:qca2064_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca2064:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:qualcomm:qca2065_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca2065:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:qualcomm:qca2066_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca2066:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:qualcomm:qca6390_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6390:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6391:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:qualcomm:qca6420_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6420:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:qualcomm:qca6430_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:qca6430:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:qualcomm:sd_8cx_gen2_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_8cx_gen2:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:qualcomm:sd_8cx_gen3_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_8cx_gen3:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:qualcomm:sd778g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd778g:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:qualcomm:sd7c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd7c:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:qualcomm:sd850_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd850:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:qualcomm:sm6250_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sm6250:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:qualcomm:wcd9340_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcd9340:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcd9341:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcd9380:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcd9385:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:qualcomm:wcn3990_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3990:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:qualcomm:wcn3991_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3991:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:qualcomm:wcn3998_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn3998:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:qualcomm:wcn6750_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn6750:-:*:*:*:*:*:*:*

  • Configuration 26:
  • cpe:/o:qualcomm:wcn6855_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn6855:-:*:*:*:*:*:*:*

  • Configuration 27:
  • cpe:/o:qualcomm:wcn6856_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wcn6856:-:*:*:*:*:*:*:*

  • Configuration 28:
  • cpe:/o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wsa8810:-:*:*:*:*:*:*:*

  • Configuration 29:
  • cpe:/o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wsa8815:-:*:*:*:*:*:*:*

  • Configuration 30:
  • cpe:/o:qualcomm:wsa8830_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wsa8830:-:*:*:*:*:*:*:*

  • Configuration 31:
  • cpe:/o:qualcomm:wsa8835_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:wsa8835:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:qualcomm:snapdragon_compute:-:*:*:*:*:*:*:*
  • OR cpe:/h:qualcomm:snapdragon_connectivity:-:*:*:*:*:*:*:*
  • OR cpe:/h:qualcomm:snapdragon_consumer_electronics_connectivity:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    qualcomm aqt1000 firmware -
    qualcomm aqt1000 -
    qualcomm qca1062 firmware -
    qualcomm qca1062 -
    qualcomm qca1064 firmware -
    qualcomm qca1064 -
    qualcomm qca2062 firmware -
    qualcomm qca2062 -
    qualcomm qca2064 firmware -
    qualcomm qca2064 -
    qualcomm qca2065 firmware -
    qualcomm qca2065 -
    qualcomm qca2066 firmware -
    qualcomm qca2066 -
    qualcomm qca6390 firmware -
    qualcomm qca6390 -
    qualcomm qca6391 firmware -
    qualcomm qca6391 -
    qualcomm qca6420 firmware -
    qualcomm qca6420 -
    qualcomm qca6430 firmware -
    qualcomm qca6430 -
    qualcomm sd 8cx gen2 firmware -
    qualcomm sd 8cx gen2 -
    qualcomm sd 8cx gen3 firmware -
    qualcomm sd 8cx gen3 -
    qualcomm sd778g firmware -
    qualcomm sd778g -
    qualcomm sd7c firmware -
    qualcomm sd7c -
    qualcomm sd850 firmware -
    qualcomm sd850 -
    qualcomm sm6250 firmware -
    qualcomm sm6250 -
    qualcomm wcd9340 firmware -
    qualcomm wcd9340 -
    qualcomm wcd9341 firmware -
    qualcomm wcd9341 -
    qualcomm wcd9380 firmware -
    qualcomm wcd9380 -
    qualcomm wcd9385 firmware -
    qualcomm wcd9385 -
    qualcomm wcn3990 firmware -
    qualcomm wcn3990 -
    qualcomm wcn3991 firmware -
    qualcomm wcn3991 -
    qualcomm wcn3998 firmware -
    qualcomm wcn3998 -
    qualcomm wcn6750 firmware -
    qualcomm wcn6750 -
    qualcomm wcn6855 firmware -
    qualcomm wcn6855 -
    qualcomm wcn6856 firmware -
    qualcomm wcn6856 -
    qualcomm wsa8810 firmware -
    qualcomm wsa8810 -
    qualcomm wsa8815 firmware -
    qualcomm wsa8815 -
    qualcomm wsa8830 firmware -
    qualcomm wsa8830 -
    qualcomm wsa8835 firmware -
    qualcomm wsa8835 -
    qualcomm snapdragon compute -
    qualcomm snapdragon connectivity -
    qualcomm snapdragon consumer electronics connectivity -