CVE-2022-25655Classic Buffer Overflow in INC Snapdragon

Severity
7.8HIGHNVD
EPSS
0.1%
top 75.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10

Description

Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon238 versions+237

🔴Vulnerability Details

1
GHSA
GHSA-5c2h-p54g-388q: Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload2023-03-10

📋Vendor Advisories

1
Android
CVE-2022-25655: Closed-source component2023-03-01