CVE-2022-25737: Use of Uninitialized Variable in MODEM
Information disclosure in modem due to missing NULL check while reading packets received from local network
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25737?
CVE-2022-25737 is an information disclosure vulnerability in a modem due to a missing NULL check while reading packets received from the local network.
Which software is affected by CVE-2022-25737?
Qualcomm Mdm8207 Firmware, Qualcomm Mdm9205 Firmware, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9207 Firmware, Qualcomm Qca4004 Firmware, Qualcomm Qts110 Firmware, Qualcomm Snapdragon Wear 1300 Firmware, Qualcomm Snapdragon X5 Lte Modem Firmware, Qualcomm Wcd9306 Firmware, and Google Android are affected by CVE-2022-25737.
What is the severity of CVE-2022-25737?
The severity of CVE-2022-25737 is high, with a severity value of 7.5.
How can I fix CVE-2022-25737?
To fix CVE-2022-25737, it is recommended to apply the security patches and updates provided by Qualcomm. Please refer to the vendor's website for more information.
Where can I find more information about CVE-2022-25737?
You can find more information about CVE-2022-25737 on the Qualcomm Product Security Bulletin for April 2023. Please visit the referenced link for details.