Buffer Over-read Vulnerability in Snapdragon WLAN Firmware
CVE-2022-33236

7.5HIGH

Summary

A buffer over-read vulnerability exists in the WLAN firmware used in several Snapdragon products. This issue arises when the firmware improperly parses cipher suite info attributes, potentially leading to a transient denial-of-service condition. Affected devices include Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, and Snapdragon Wired Infrastructure and Networking. Users and organizations utilizing these products should be aware of the potential impacts and apply relevant security updates as they become available.

Affected Version(s)

Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking AR8035

Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking CSR8811

Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking IPQ5010

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.