PT-2021-7410 · Qualcomm · Qualcomm Snapdragon Industrial Iot+4

Published

2021-11-02

·

Updated

2023-08-08

·

CVE-2022-25654

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Auto (affected versions not specified) Qualcomm Snapdragon Connectivity (affected versions not specified) Qualcomm Snapdragon Consumer IOT (affected versions not specified) Qualcomm Snapdragon Industrial IOT (affected versions not specified) Qualcomm Snapdragon Wearables (affected versions not specified)
Description The issue is related to memory corruption in the kernel due to improper input validation while processing ION commands. This can allow an attacker to cause a denial of service or execute arbitrary code. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For Qualcomm Snapdragon Auto, update to a version that includes proper input validation for ION commands. For Qualcomm Snapdragon Connectivity, update to a version that includes proper input validation for ION commands. For Qualcomm Snapdragon Consumer IOT, update to a version that includes proper input validation for ION commands. For Qualcomm Snapdragon Industrial IOT, update to a version that includes proper input validation for ION commands. For Qualcomm Snapdragon Wearables, update to a version that includes proper input validation for ION commands. As a temporary workaround, consider restricting access to the ION command processing functionality until a patch is available.

Fix

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2022-06023
CVE-2022-25654

Affected Products

Qualcomm Snapdragon Auto
Qualcomm Snapdragon Connectivity
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Industrial Iot
Qualcomm Snapdragon Wearables