First published: Tue Apr 04 2023(Updated: )
Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length.
Credit: product-security@qualcomm.com product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM8207 | ||
Qualcomm MDM8207 Firmware | ||
Qualcomm 9205 Firmware | ||
Qualcomm 9205 | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
qualcomm MDM9207C firmware | ||
qualcomm MDM9207C firmware | ||
Qualcomm QCA4004 Firmware | ||
Qualcomm QCA4004 Firmware | ||
Qualcomm QTS110 | ||
Qualcomm QTS110 | ||
Qualcomm Snapdragon 1100 Wearable | ||
Qualcomm Snapdragon Wear 1100 Firmware | ||
Qualcomm Snapdragon 1200 Wearable Firmware | ||
Qualcomm Snapdragon 1200 Wearable Firmware | ||
Qualcomm Snapdragon Wear 1300 Firmware | ||
Qualcomm Snapdragon Wear 1300 Platform Firmware | ||
Qualcomm Snapdragon X5 LTE Firmware | ||
Qualcomm Snapdragon X5 LTE | ||
Qualcomm WCD9306 | ||
Qualcomm WCD9306 | ||
Qualcomm WCD9330 | ||
Qualcomm WCD9330 Firmware | ||
All of | ||
Qualcomm MDM8207 | ||
Qualcomm MDM8207 Firmware | ||
All of | ||
Qualcomm 9205 Firmware | ||
Qualcomm 9205 | ||
All of | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
All of | ||
qualcomm MDM9207C firmware | ||
qualcomm MDM9207C firmware | ||
All of | ||
Qualcomm QCA4004 Firmware | ||
Qualcomm QCA4004 Firmware | ||
All of | ||
Qualcomm QTS110 | ||
Qualcomm QTS110 | ||
All of | ||
Qualcomm Snapdragon 1100 Wearable | ||
Qualcomm Snapdragon Wear 1100 Firmware | ||
All of | ||
Qualcomm Snapdragon 1200 Wearable Firmware | ||
Qualcomm Snapdragon 1200 Wearable Firmware | ||
All of | ||
Qualcomm Snapdragon Wear 1300 Firmware | ||
Qualcomm Snapdragon Wear 1300 Platform Firmware | ||
All of | ||
Qualcomm Snapdragon X5 LTE Firmware | ||
Qualcomm Snapdragon X5 LTE | ||
All of | ||
Qualcomm WCD9306 | ||
Qualcomm WCD9306 | ||
All of | ||
Qualcomm WCD9330 | ||
Qualcomm WCD9330 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-33295 is high, with a severity value of 7.5.
The following software is affected by CVE-2022-33295: Qualcomm Mdm8207 Firmware, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9207 Firmware, Qualcomm Qts110 Firmware, Qualcomm Snapdragon Wear 1300 Firmware, Qualcomm Snapdragon X5 Lte Modem Firmware, Qualcomm Wcd9306 Firmware, Google Android.
CVE-2022-33295 is an information disclosure vulnerability in Modem due to a buffer over-read while parsing the wms message received.
To fix CVE-2022-33295, it is recommended to apply the patches provided by Qualcomm. Please refer to the reference link for more information.
You can find more information about CVE-2022-33295 in the April 2023 bulletin on the Qualcomm website.