VDB

CVE-2022-25728

CVE-2022-25728 PUBLISHED CVSS 8.2 HIGH

Reported by qualcomm · Published February 9, 2023

Information disclosure in modem due to buffer over-read while processing response from DNS server

Risk Scores

CVSS 3.1
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Affected Products

VendorProductVersions
Qualcomm, Inc.SnapdragonAR8031, CSRA6620, CSRA6640
qualcommsxr2230p_firmware*
qualcommmdm9205_firmware*
qualcommar8031_firmware*
qualcommwcd9335_firmware*
qualcommsxr1230p_firmware*
qualcommqca4004_firmware*
qualcommmdm8207_firmware*
qualcommmdm9206_firmware*
qualcommssg2115p_firmware*
qualcommwcn7851_firmware*
qualcommmdm9607_firmware*
qualcommqca4020_firmware*
Qualcomm, Inc.Snapdragon*, SSG2125P, SXR1230P
qualcommwcn3980_firmware*
qualcommwcn3998_firmware*
qualcommqcs405_firmware*
qualcommwsa8815_firmware*
qualcommwcn7850_firmware*
qualcommwcn6856_firmware*

…and 16 more

Timeline

  • Feb 9, 2023 EPSS Score
  • Feb 9, 2023 CVE Published
  • Mar 7, 2023 EPSS Score
  • Mar 21, 2023 EPSS Score
  • Apr 30, 2023 EPSS Score
  • Jun 9, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
  • Aug 27, 2023 EPSS Score
  • Oct 6, 2023 EPSS Score
  • Nov 15, 2023 EPSS Score
  • Dec 25, 2023 EPSS Score
  • Feb 3, 2024 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›