CVE-2022-22069: High severity qualcomm aqt1000 firmware vulnerability
Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22069?
CVE-2022-22069 is classified as a high severity vulnerability due to its potential to expose sensitive cryptographic data.
How do I fix CVE-2022-22069?
To address CVE-2022-22069, ensure that key protect is enabled on affected devices and apply any available firmware updates from Qualcomm.
What are the affected Qualcomm products for CVE-2022-22069?
CVE-2022-22069 affects various Qualcomm firmware products, including those in Snapdragon Auto, Compute, Connectivity, and Mobile categories.
Is CVE-2022-22069 present in all Android devices?
No, CVE-2022-22069 specifically affects devices with vulnerable Qualcomm chipsets that have the key protect feature disabled.
What is the impact of CVE-2022-22069 on device security?
The impact of CVE-2022-22069 includes the potential for unauthorized decryption of sensitive information stored in the keybox.