CVE-2022-33274
HIGHCVSS 7.8/10EPSS 0.12%
Last modified
CVE-2022-33274 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Memory corruption in android core due to improper validation of array index while returning feature ids after license authentication.. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
Memory corruption in android core due to improper validation of array index while returning feature ids after license authentication.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Qam8295p Firmware | All versions |
| Qualcomm | Qca6574au Firmware | All versions |
| Qualcomm | Qca6696 Firmware | All versions |
| Qualcomm | Sa6145p Firmware | All versions |
| Qualcomm | Sa6150p Firmware | All versions |
| Qualcomm | Sa6155p Firmware | All versions |
| Qualcomm | Sa8145p Firmware | All versions |
| Qualcomm | Sa8150p Firmware | All versions |
| Qualcomm | Sa8155p Firmware | All versions |
| Qualcomm | Sa8195p Firmware | All versions |
| Qualcomm | Sa8295p Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-33274?
Memory corruption in android core due to improper validation of array index while returning feature ids after license authentication.
How severe is CVE-2022-33274?
CVE-2022-33274 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.12% probability of exploitation in the next 30 days.
How do I fix CVE-2022-33274?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-33269Memory corruption due to integer overflow or wraparound in C…7.8
- CVE-2022-3327Missing Authentication for Critical Function in GitHub repos…9.8
- CVE-2022-33270Transient DOS due to time-of-check time-of-use race conditio…5.9
- CVE-2022-33271Information disclosure due to buffer over-read in WLAN while…7.5
- CVE-2022-33272Transient DOS in modem due to reachable assertion.7.5
- CVE-2022-33273Information disclosure due to buffer over-read in Trusted Ex…5.5
- CVE-2022-33275Memory corruption due to improper validation of array index …7.8
- CVE-2022-33276Memory corruption due to buffer copy without checking size o…7.8
- CVE-2022-33277Memory corruption in modem due to buffer copy without checki…7.8
- CVE-2022-33278Memory corruption due to buffer copy without checking the si…7.8
- CVE-2022-33279Memory corruption due to stack based buffer overflow in WLAN…9.8
- CVE-2022-3328Race condition in snap-confine's must_mkdir_and_open_with_pe…7
Are you affected by CVE-2022-33274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
