First published: Tue Apr 04 2023(Updated: )
Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length.
Credit: product-security@qualcomm.com product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Mdm8207 Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Mdm9206 Firmware | ||
Qualcomm Mdm9206 | ||
Qualcomm Mdm9207 Firmware | ||
Qualcomm Mdm9207 | ||
Google Android | ||
Qualcomm Qca4004 | ||
Qualcomm Qts110 Firmware | ||
Qualcomm Qts110 | ||
Qualcomm Snapdragon Wear 1300 Firmware | ||
Qualcomm Snapdragon Wear 1300 | ||
Qualcomm Snapdragon X5 Lte Modem Firmware | ||
Qualcomm Snapdragon X5 Lte Modem | ||
Qualcomm Wcd9306 Firmware | ||
Google Android | ||
Google Android | ||
Qualcomm Wcd9330 | ||
All of | ||
Qualcomm Mdm8207 Firmware | ||
Google Android | ||
All of | ||
Google Android | ||
Google Android | ||
All of | ||
Qualcomm Mdm9206 Firmware | ||
Qualcomm Mdm9206 | ||
All of | ||
Qualcomm Mdm9207 Firmware | ||
Qualcomm Mdm9207 | ||
All of | ||
Google Android | ||
Qualcomm Qca4004 | ||
All of | ||
Qualcomm Qts110 Firmware | ||
Qualcomm Qts110 | ||
All of | ||
Qualcomm Snapdragon Wear 1100 Firmware | ||
Qualcomm Snapdragon Wear 1100 | ||
All of | ||
Qualcomm Snapdragon Wear 1200 Firmware | ||
Qualcomm Snapdragon Wear 1200 | ||
All of | ||
Qualcomm Snapdragon Wear 1300 Firmware | ||
Qualcomm Snapdragon Wear 1300 | ||
All of | ||
Qualcomm Snapdragon X5 Lte Modem Firmware | ||
Qualcomm Snapdragon X5 Lte Modem | ||
All of | ||
Qualcomm Wcd9306 Firmware | ||
Google Android | ||
All of | ||
Google Android | ||
Qualcomm Wcd9330 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-33295 is high, with a severity value of 7.5.
The following software is affected by CVE-2022-33295: Qualcomm Mdm8207 Firmware, Qualcomm Mdm9206 Firmware, Qualcomm Mdm9207 Firmware, Qualcomm Qts110 Firmware, Qualcomm Snapdragon Wear 1300 Firmware, Qualcomm Snapdragon X5 Lte Modem Firmware, Qualcomm Wcd9306 Firmware, Google Android.
CVE-2022-33295 is an information disclosure vulnerability in Modem due to a buffer over-read while parsing the wms message received.
To fix CVE-2022-33295, it is recommended to apply the patches provided by Qualcomm. Please refer to the reference link for more information.
You can find more information about CVE-2022-33295 in the April 2023 bulletin on the Qualcomm website.