Memory Corruption in Snapdragon IoT and Audio Products by Qualcomm
CVE-2022-25727

9.8CRITICAL

Key Information:

Summary

This vulnerability involves memory corruption in Qualcomm's Snapdragon platform due to an improper length check while copying data into memory. This issue affects various products in the Snapdragon Consumer IoT, Industrial IoT, and Voice & Music categories. When exploited, it could lead to unexpected behavior, potentially exposing systems to further risks.

Affected Version(s)

Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music AR8031

Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music CSRA6620

Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music CSRA6640

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.