← Vulnerability feed

Vulnerability record · CVE-2022-40503 · published 13 April 2023

CVE-2022-40503: Qualcomm 9206 lte modem firmware out-of-bounds read vulnerability

Qualcomm · 9206 Lte Modem Firmware

Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.

7.5 CVSS 3.1 High EPSS 0.41% · top 67.4% CWE-126 · CWE-126CWE-125 · Out-of-bounds read
7.5CVSS 3.1 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
150Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

150 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-40503 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22388Qualcomm 315 5g iot modem firmware out-of-bounds write vulnerabilityMemory Corruption in Multi-mode Call Processor while processing bit mask API.EPSS 0.35%9.8CVE-2023-22385Qualcomm 315 5g iot modem firmware out-of-bounds write vulnerabilityMemory Corruption in Data Modem while making a MO call or MT VOLTE call.EPSS 0.42%8.2CVE-2024-23359Qualcomm qcn9024 firmware vulnerabilityInformation disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.EPSS 0.26%7.8CVE-2025-47320Qualcomm 9206 lte modem firmware out-of-bounds write vulnerabilityMemory corruption while processing MFC channel configuration during music playback.EPSS 0.08%7.8CVE-2025-27053Qualcomm 315 5g iot modem firmware vulnerabilityMemory corruption during PlayReady APP usecase while processing TA commands.EPSS 0.09%7.8CVE-2024-33056Qualcomm 315 5g iot modem firmware out-of-bounds read vulnerabilityMemory corruption when allocating and accessing an entry in an SMEM partition continuously.EPSS 0.10%7.8CVE-2018-11816Qualcomm 9206 lte modem firmware use after free vulnerabilityCrafted Binder Request Causes Heap UAF in MediaServerEPSS 0.11%7.8CVE-2016-10408Qualcomm 9206 lte modem firmware improper access control vulnerabilityQSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid ex…EPSS 0.11%

Source: NIST National Vulnerability Database (record CVE-2022-40503), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.