CVE-2022-25705Integer Overflow to Buffer Overflow in INC Snapdragon

Severity
7.8HIGHNVD
EPSS
0.1%
top 74.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10

Description

Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5qualcomm_inc/snapdragon201 versions+200

🔴Vulnerability Details

1
GHSA
GHSA-w9cc-3843-6mhx: Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response2023-03-10

📋Vendor Advisories

1
Android
CVE-2022-25705: Closed-source component2023-03-01