VDB

CVE-2022-25690

CVE-2022-25690 PUBLISHED CVSS 7.5 HIGH

Information disclosure in WLAN due to improper validation of array index while parsing crafted ANQP action frames in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

EPSS 0.30% · 53.4th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.30%
53.4th percentile

Affected Products

VendorProductVersions
qualcommcsra6620_firmware
qualcommsd888_firmware
qualcommsd_8cx_gen3_firmware
qualcommsd678_firmware
qualcommqca6420_firmware
qualcommqcs6125_firmware
qualcommsd_8_gen1_5g_firmware
qualcommsa6155_firmware
qualcommwcn6740_firmware
qualcommsd712_firmware
qualcommcsrb31024_firmware
qualcommwcn6856_firmware
qualcommmsm8996au_firmware
qualcommwcd9326_firmware
qualcommsa6145p_firmware
qualcommar8031_firmware
qualcommqca6696_firmware
qualcommsd670_firmware
qualcommsd7c_firmware
qualcommqca6436_firmware

…and 133 more

Timeline

  • Sep 7, 2022 CVE Published
  • Sep 16, 2022 EPSS Score
  • Oct 31, 2022 EPSS Score
  • Dec 15, 2022 EPSS Score
  • Jan 29, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 15, 2023 EPSS Score
  • Apr 28, 2023 EPSS Score
  • Jun 12, 2023 EPSS Score
  • Jul 27, 2023 EPSS Score
  • Sep 10, 2023 EPSS Score
  • Oct 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›