9.0
CRITICAL
CVE-2022-25652
Snapdragon Wired Infrastructure and Networking Cryptographic Hash Verification Weakness
Description

Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking

INFO

Published Date :

Sept. 16, 2022, 6:15 a.m.

Last Modified :

Nov. 21, 2024, 6:52 a.m.

Remotely Exploitable :

No

Impact Score :

5.8

Exploitability Score :

2.5
Affected Products

The following products are affected by CVE-2022-25652 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Qualcomm csr8811_firmware
2 Qualcomm ipq5010_firmware
3 Qualcomm ipq5028_firmware
4 Qualcomm ipq6000_firmware
5 Qualcomm ipq6010_firmware
6 Qualcomm ipq6018_firmware
7 Qualcomm ipq6028_firmware
8 Qualcomm ipq8070_firmware
9 Qualcomm ipq8070a_firmware
10 Qualcomm ipq8071_firmware
11 Qualcomm ipq8071a_firmware
12 Qualcomm ipq8072_firmware
13 Qualcomm ipq8072a_firmware
14 Qualcomm ipq8074_firmware
15 Qualcomm ipq8074a_firmware
16 Qualcomm ipq8076_firmware
17 Qualcomm ipq8076a_firmware
18 Qualcomm ipq8078_firmware
19 Qualcomm ipq8078a_firmware
20 Qualcomm ipq8173_firmware
21 Qualcomm ipq8174_firmware
22 Qualcomm pmp8074_firmware
23 Qualcomm qca4024_firmware
24 Qualcomm qca6428_firmware
25 Qualcomm qca6438_firmware
26 Qualcomm qca8072_firmware
27 Qualcomm qca8075_firmware
28 Qualcomm qca8081_firmware
29 Qualcomm qca9888_firmware
30 Qualcomm qca9889_firmware
31 Qualcomm qcn5021_firmware
32 Qualcomm qcn5022_firmware
33 Qualcomm qcn5024_firmware
34 Qualcomm qcn5052_firmware
35 Qualcomm qcn5054_firmware
36 Qualcomm qcn5122_firmware
37 Qualcomm qcn5124_firmware
38 Qualcomm qcn5152_firmware
39 Qualcomm qcn5154_firmware
40 Qualcomm qcn5164_firmware
41 Qualcomm qcn6023_firmware
42 Qualcomm qcn6024_firmware
43 Qualcomm qcn6100_firmware
44 Qualcomm qcn6102_firmware
45 Qualcomm qcn6112_firmware
46 Qualcomm qcn6122_firmware
47 Qualcomm qcn6132_firmware
48 Qualcomm qcn9000_firmware
49 Qualcomm qcn9012_firmware
50 Qualcomm qcn9022_firmware
51 Qualcomm qcn9024_firmware
52 Qualcomm qcn9070_firmware
53 Qualcomm qcn9072_firmware
54 Qualcomm qcn9074_firmware
55 Qualcomm qcn9100_firmware
56 Qualcomm ipq5018_firmware
57 Qualcomm qcn5064_firmware
58 Qualcomm qcn5550_firmware
59 Qualcomm ipq6005_firmware
60 Qualcomm qcn5121_firmware
61 Qualcomm csr8811
62 Qualcomm ipq6000
63 Qualcomm ipq6005
64 Qualcomm ipq6010
65 Qualcomm ipq6018
66 Qualcomm ipq6028
67 Qualcomm ipq8070
68 Qualcomm ipq8070a
69 Qualcomm ipq8071
70 Qualcomm ipq8071a
71 Qualcomm ipq8072
72 Qualcomm ipq8072a
73 Qualcomm ipq8074
74 Qualcomm ipq8074a
75 Qualcomm ipq8076
76 Qualcomm ipq8076a
77 Qualcomm ipq8078
78 Qualcomm ipq8078a
79 Qualcomm ipq8173
80 Qualcomm ipq8174
81 Qualcomm qca4024
82 Qualcomm qca6428
83 Qualcomm qca6438
84 Qualcomm qca8072
85 Qualcomm qca8075
86 Qualcomm qca8081
87 Qualcomm qca9888
88 Qualcomm qca9889
89 Qualcomm qcn5021
90 Qualcomm qcn5022
91 Qualcomm qcn5024
92 Qualcomm qcn5052
93 Qualcomm qcn5054
94 Qualcomm qcn5064
95 Qualcomm qcn5121
96 Qualcomm qcn5122
97 Qualcomm qcn5124
98 Qualcomm qcn5152
99 Qualcomm qcn5154
100 Qualcomm qcn5164
101 Qualcomm qcn5550
102 Qualcomm qcn9000
103 Qualcomm qcn9074
104 Qualcomm ipq5010
105 Qualcomm ipq5018
106 Qualcomm pmp8074
107 Qualcomm qcn6023
108 Qualcomm qcn6024
109 Qualcomm qcn9012
110 Qualcomm qcn9022
111 Qualcomm qcn9024
112 Qualcomm qcn9070
113 Qualcomm qcn9072
114 Qualcomm qcn9100
115 Qualcomm ipq5028
116 Qualcomm qcn6112
117 Qualcomm qcn6122
118 Qualcomm qcn6132
119 Qualcomm qcn6100
120 Qualcomm qcn6102
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2022-25652.

URL Resource
https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletin Vendor Advisory
https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletin Vendor Advisory

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2022-25652 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2022-25652 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletin
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • Initial Analysis by [email protected]

    Sep. 20, 2022

    Action Type Old Value New Value
    Added CVSS V3.1 NIST AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Changed Reference Type https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletin No Types Assigned https://www.qualcomm.com/company/product-security/bulletins/september-2022-bulletin Vendor Advisory
    Added CWE NIST CWE-287
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:csr8811_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:csr8811:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq5010_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq5010:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq5018_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq5018:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq5028_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq5028:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq6000_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq6000:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq6005_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq6005:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq6010_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq6010:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq6018_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq6018:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq6028_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq6028:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8070_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8070:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8070a_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8070a:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8071_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8071:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8071a_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8071a:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8072_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8072:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8072a_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8072a:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8074_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8074:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8074a_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8074a:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8076_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8076:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8076a_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8076a:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8078_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8078:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8078a_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8078a:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8173_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8173:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:ipq8174_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:ipq8174:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:pmp8074_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:pmp8074:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca4024_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca4024:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca6428_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca6428:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca6438_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca6438:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca8072_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca8072:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca8075_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca8075:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca8081_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca8081:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca9888_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca9888:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qca9889_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qca9889:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5021_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5021:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5022_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5022:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5024_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5024:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5052_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5052:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5054_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5054:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5064_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5064:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5121_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5121:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5122_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5122:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5124_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5124:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5152_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5152:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5154_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5154:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5164_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5164:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn5550_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn5550:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6023_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6023:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6024_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6024:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6100_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6100:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6102_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6102:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6112_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6112:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6122_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6122:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn6132_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn6132:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9000_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9000:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9012_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9012:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9022_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9022:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9024_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9024:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9070_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9070:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9072_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9072:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9074_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9074:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:qualcomm:qcn9100_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:qualcomm:qcn9100:-:*:*:*:*:*:*:*
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2022-25652 is associated with the following CWEs:

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

0.04 }} 0.00%

score

0.11216

percentile

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability