CVE-2022-25719

CRITICALCVSS 9.1/10EPSS 0.46%

Last modified

CVE-2022-25719 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. EPSS estimates a 0.46% chance of exploitation in the next 30 days.

Description

Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

Metrics

CVSS 3.1
9.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS Probability
0.46%

36.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
QualcommApq8009 FirmwareAll versions
QualcommApq8009w FirmwareAll versions
QualcommApq8016 FirmwareAll versions
QualcommApq8017 FirmwareAll versions
QualcommApq8037 FirmwareAll versions
QualcommApq8052 FirmwareAll versions
QualcommApq8053 FirmwareAll versions
QualcommApq8056 FirmwareAll versions
QualcommApq8076 FirmwareAll versions
QualcommApq8084 FirmwareAll versions
QualcommAr8031 FirmwareAll versions
QualcommCsr8811 FirmwareAll versions
QualcommCsra6620 FirmwareAll versions
QualcommCsra6640 FirmwareAll versions
QualcommIpq5010 FirmwareAll versions
QualcommIpq5018 FirmwareAll versions
QualcommIpq5028 FirmwareAll versions
QualcommIpq6000 FirmwareAll versions
QualcommIpq6010 FirmwareAll versions
QualcommIpq6018 FirmwareAll versions
QualcommIpq6028 FirmwareAll versions
QualcommIpq8070a FirmwareAll versions
QualcommIpq8071a FirmwareAll versions
QualcommIpq8072a FirmwareAll versions
QualcommIpq8074a FirmwareAll versions
QualcommIpq8076 FirmwareAll versions
QualcommIpq8076a FirmwareAll versions
QualcommIpq8078 FirmwareAll versions
QualcommIpq8078a FirmwareAll versions
QualcommIpq8173 FirmwareAll versions
QualcommIpq8174 FirmwareAll versions
QualcommMdm9205 FirmwareAll versions
QualcommMdm9225 FirmwareAll versions
QualcommMdm9225m FirmwareAll versions
QualcommMdm9230 FirmwareAll versions
QualcommMdm9235m FirmwareAll versions
QualcommMdm9330 FirmwareAll versions
QualcommMdm9625 FirmwareAll versions
QualcommMdm9625m FirmwareAll versions
QualcommMdm9630 FirmwareAll versions
QualcommMdm9635m FirmwareAll versions
QualcommMsm8108 FirmwareAll versions
QualcommMsm8208 FirmwareAll versions
QualcommMsm8209 FirmwareAll versions
QualcommMsm8608 FirmwareAll versions
QualcommMsm8909w FirmwareAll versions
QualcommMsm8917 FirmwareAll versions
QualcommMsm8920 FirmwareAll versions
QualcommMsm8937 FirmwareAll versions
QualcommMsm8940 FirmwareAll versions

Showing 50 of 118 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-25719?
Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
How severe is CVE-2022-25719?
CVE-2022-25719 has a CVSS score of 9.1/10 (CRITICAL severity). The EPSS model estimates a 0.46% probability of exploitation in the next 30 days.
How do I fix CVE-2022-25719?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-25719?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST