CVE-2022-25745: Always Incorrect Control Flow Implementation in MODEM
Published Apr 4, 2023
·Updated
Memory corruption in modem due to improper input validation while handling the incoming CoAP message
Affected Software
20 affected components
All of the following
QUALCOMM Mdm9205 Firmware
QUALCOMM MDM9205
All of the following
QUALCOMM Qca4004 Firmware
QUALCOMM Qca4004
All of the following
QUALCOMM Qts110 Firmware
QUALCOMM Qts110
All of the following
QUALCOMM Snapdragon Wear 1300 Firmware
QUALCOMM Snapdragon Wear 1300
All of the following
QUALCOMM Wcd9306 Firmware
Qualcomm Wcd9306
QUALCOMM Mdm9205 Firmware
QUALCOMM MDM9205
QUALCOMM Qca4004 Firmware
QUALCOMM Qca4004
QUALCOMM Qts110 Firmware
QUALCOMM Qts110
QUALCOMM Snapdragon Wear 1300 Firmware
QUALCOMM Snapdragon Wear 1300
QUALCOMM Wcd9306 Firmware
Qualcomm Wcd9306
Event History
Apr 4, 2023
CVE Published
via MITRE·04:46 AM
Data Sourced
via MITRE·04:46 AM
DescriptionSeverityWeakness
Apr 13, 2023
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-25745?
CVE-2022-25745 is a vulnerability that causes memory corruption in the modem due to improper input validation while handling the incoming CoAP message.
2
Which software is affected by CVE-2022-25745?
The affected software includes Google Android with Qualcomm MDM9205 firmware, Qualcomm QCA4004 with Google Android firmware, Qualcomm Qts110 Firmware, and Qualcomm Snapdragon Wear 1300 Firmware.
3
What is the severity of CVE-2022-25745?
The severity of CVE-2022-25745 is critical, with a CVSS score of 9.8.
4
How can I fix CVE-2022-25745?
To fix CVE-2022-25745, it is recommended to apply the latest security patches provided by your software vendor.
5
Is Qualcomm QCA4004 vulnerable to CVE-2022-25745?
No, Qualcomm QCA4004 is not vulnerable to CVE-2022-25745.