CVE-2022-25663

MEDIUM

Qualcomm Aqt1000 Firmware - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

Possible buffer overflow due to lack of buffer length check during management frame Rx handling lead to denial of service in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 32.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (31)
qualcomm/aqt1000_firmware
qualcomm/qca1062_firmware
qualcomm/qca1064_firmware
qualcomm/qca2062_firmware
qualcomm/qca2064_firmware
qualcomm/qca2065_firmware
qualcomm/qca2066_firmware
qualcomm/qca6390_firmware
qualcomm/qca6391_firmware
qualcomm/qca6420_firmware
... and 21 more
Published Oct 19, 2022
Tracked Since Feb 18, 2026