CVE-2022-33259: Buffer copy without checking the size of input in Modem
Published Apr 4, 2023
·Updated
Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.
Affected Software
48 affected components
QUALCOMM Mdm8207 Firmware
QUALCOMM Mdm8207
QUALCOMM Mdm9205 Firmware
QUALCOMM MDM9205
QUALCOMM Mdm9206 Firmware
QUALCOMM MDM9206
QUALCOMM Mdm9207 Firmware
QUALCOMM Mdm9207
QUALCOMM Qca4004 Firmware
QUALCOMM Qca4004
QUALCOMM Qts110 Firmware
QUALCOMM Qts110
QUALCOMM Snapdragon Wear 1100 Firmware
QUALCOMM Snapdragon Wear 1100
QUALCOMM Snapdragon Wear 1200 Firmware
QUALCOMM Snapdragon Wear 1200
QUALCOMM Snapdragon Wear 1300 Firmware
QUALCOMM Snapdragon Wear 1300
QUALCOMM Snapdragon X5 Lte Modem Firmware
QUALCOMM Snapdragon X5 Lte Modem
QUALCOMM Wcd9306 Firmware
Qualcomm Wcd9306
Qualcomm Wcd9330 Firmware
QUALCOMM Wcd9330
All of the following
QUALCOMM Mdm8207 Firmware
QUALCOMM Mdm8207
All of the following
QUALCOMM Mdm9205 Firmware
QUALCOMM MDM9205
All of the following
QUALCOMM Mdm9206 Firmware
QUALCOMM MDM9206
All of the following
QUALCOMM Mdm9207 Firmware
QUALCOMM Mdm9207
All of the following
QUALCOMM Qca4004 Firmware
QUALCOMM Qca4004
All of the following
QUALCOMM Qts110 Firmware
QUALCOMM Qts110
All of the following
QUALCOMM Snapdragon Wear 1100 Firmware
QUALCOMM Snapdragon Wear 1100
All of the following
QUALCOMM Snapdragon Wear 1200 Firmware
QUALCOMM Snapdragon Wear 1200
All of the following
QUALCOMM Snapdragon Wear 1300 Firmware
QUALCOMM Snapdragon Wear 1300
All of the following
QUALCOMM Snapdragon X5 Lte Modem Firmware
QUALCOMM Snapdragon X5 Lte Modem
All of the following
QUALCOMM Wcd9306 Firmware
Qualcomm Wcd9306
All of the following
Qualcomm Wcd9330 Firmware
QUALCOMM Wcd9330
Event History
Apr 4, 2023
CVE Published
via MITRE·04:46 AM
Data Sourced
via MITRE·04:46 AM
DescriptionSeverityWeakness
Apr 13, 2023
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-33259.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.'
3
What is the severity of CVE-2022-33259?
The severity of CVE-2022-33259 is critical with a severity value of 9.8.
4
Which software is affected by CVE-2022-33259?
The Qualcomm Mdm8207 Firmware and the Qualcomm Mdm9206 Firmware are affected by CVE-2022-33259.
5
How can I fix CVE-2022-33259?
To fix CVE-2022-33259, it is recommended to update to the latest firmware provided by Qualcomm.