CVE-2022-33296

MEDIUM

Qualcomm Modem Firmware - Memory Corruption via Integer Overflow

Title source: llm
STIX 2.1

Description

Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.

Scores

CVSS v3 5.9
EPSS 0.0012
EPSS Percentile 30.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190 CWE-680
Status published
Products (50)
qualcomm/315_5g_iot_modem_firmware
qualcomm/8905_firmware
qualcomm/8909_firmware
qualcomm/8917_firmware
qualcomm/apq8017_firmware
qualcomm/aqt1000_firmware
qualcomm/ar8035_firmware
qualcomm/csrb31024_firmware
qualcomm/mdm9628_firmware
qualcomm/qca6310_firmware
... and 40 more
Published Apr 13, 2023
Tracked Since Feb 18, 2026