CVE-2022-22066 Vulnerability Details
                
					
						
					   /   
					
					
						
					   /   
					
					
						
					   /   
					
					
						
					
					
					
					
					
CVE-2022-22066 Metadata Quick Info
					CVE Published: 16/09/2022 | 
					
CVE Updated: 03/08/2024 | 
					
CVE Year: 2022 
					
					Source:  qualcomm | 
					
Vendor:  Qualcomm, Inc. | 
					
Product: Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables 
					
					
					Status : PUBLISHED 
					
 
					
					CVE-2022-22066 Description
					 
					Memory corruption occurs while processing command received from HLOS due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables					
					
					
Metrics
					CVSS Version: 3.1 | 
					
Base Score: 8.4 HIGH
					Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 
					
					l➤ Exploitability Metrics:
						     Attack Vector (AV)* LOCAL 
						     Attack Complexity (AC)* LOW 
						     Privileges Required (PR)* NONE 
						     User Interaction (UI)* NONE 
						     Scope (S)* UNCHANGED 
  			
					l➤ Impact Metrics:
						     Confidentiality Impact (C)* HIGH 
						     Integrity Impact (I)* HIGH 
						     Availability Impact (A)* HIGH 
					
					Weakness Enumeration (CWE)
					CWE-ID:  
					CWE Name: Buffer Over-read in content Protection 
					Source: Qualcomm, Inc. 
					
					Common Attack Pattern Enumeration and Classification (CAPEC)
					CAPEC-ID:  
					CAPEC Description:  
					
					
						Source: NVD (National Vulnerability Database).