CVE-2022-25691Reachable Assertion in INC Snapdragon Mobile

Severity
7.5HIGHNVD
EPSS
0.4%
top 41.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13

Description

Denial of service in Modem due to reachable assertion while processing SIB1 with invalid SCS and bandwidth settings in Snapdragon Mobile

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon_mobile24 versions+23

🔴Vulnerability Details

1
GHSA
GHSA-jm38-h5c6-fxwq: Denial of service in Modem due to reachable assertion while processing SIB1 with invalid SCS and bandwidth settings in Snapdragon Mobile2022-12-13

📋Vendor Advisories

1
Android
CVE-2022-25691: Closed-source component2022-12-01