PT-2021-7403 · Qualcomm · Qualcomm Embedded Platform

Published

2021-07-04

·

Updated

2023-04-19

·

CVE-2022-25656

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qualcomm embedded platform software (affected versions not specified)
Description The issue is related to an integer overflow in the Qualcomm embedded platform software, which can lead to memory corruption. This can be exploited to cause a denial of service or execute arbitrary code. The vulnerability is due to improper validation of buffer size sent to write to console when computing the payload size in various Snapdragon products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, and Snapdragon Wearables.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-06009
CVE-2022-25656

Affected Products

Qualcomm Embedded Platform