CVE-2022-25690 PUBLISHED CVSS 7.5 HIGH

Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

EPSS 0.30% · 52.9th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.30%
52.9th percentile

Affected Products

VendorProductVersions
qualcommcsra6620_firmware
qualcommsd888_firmware
qualcommsd_8cx_gen3_firmware
qualcommsd678_firmware
qualcommqca6420_firmware
qualcommqcs6125_firmware
qualcommsd_8_gen1_5g_firmware
qualcommsa6155_firmware
qualcommwcn6740_firmware
qualcommsd712_firmware
qualcommcsrb31024_firmware
qualcommwcn6856_firmware
qualcommmsm8996au_firmware
qualcommwcd9326_firmware
qualcommsa6145p_firmware
qualcommar8031_firmware
qualcommqca6696_firmware
qualcommsd670_firmware
qualcommsd7c_firmware
qualcommqca6436_firmware

…and 133 more

Timeline

References

Open in Interactive Console →