Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.
Conclusion & alert: CVE-2022-33280 is rated Moderate Risk (48.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.31%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-17 | 0.16% | 0.31% | +0.15% |
| 2 | 2026-03-08 | 0.10% | 0.16% | +0.05% |
| 3 | 2025-11-21 | — | 0.10% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.1 | HIGH |
|
3.9 | 3.4 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| qualcomm | apq8096au_firmware | — | cpe:2.3:o:qualcomm:apq8096au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | ar8031_firmware | — | cpe:2.3:o:qualcomm:ar8031_firmware:-:*:*:*:*:*:*:* |
| qualcomm | ar8035_firmware | — | cpe:2.3:o:qualcomm:ar8035_firmware:-:*:*:*:*:*:*:* |
| qualcomm | csra6620_firmware | — | cpe:2.3:o:qualcomm:csra6620_firmware:-:*:*:*:*:*:*:* |
| qualcomm | csra6640_firmware | — | cpe:2.3:o:qualcomm:csra6640_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9150_firmware | — | cpe:2.3:o:qualcomm:mdm9150_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9250_firmware | — | cpe:2.3:o:qualcomm:mdm9250_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9628_firmware | — | cpe:2.3:o:qualcomm:mdm9628_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9650_firmware | — | cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6174a_firmware | — | cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6391_firmware | — | cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6564a_firmware | — | cpe:2.3:o:qualcomm:qca6564a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6564au_firmware | — | cpe:2.3:o:qualcomm:qca6564au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574a_firmware | — | cpe:2.3:o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574au_firmware | — | cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6584au_firmware | — | cpe:2.3:o:qualcomm:qca6584au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6595au_firmware | — | cpe:2.3:o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca8081_firmware | — | cpe:2.3:o:qualcomm:qca8081_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca8337_firmware | — | cpe:2.3:o:qualcomm:qca8337_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca9377_firmware | — | cpe:2.3:o:qualcomm:qca9377_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn6024_firmware | — | cpe:2.3:o:qualcomm:qcn6024_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn9011_firmware | — | cpe:2.3:o:qualcomm:qcn9011_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn9012_firmware | — | cpe:2.3:o:qualcomm:qcn9012_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn9024_firmware | — | cpe:2.3:o:qualcomm:qcn9024_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn9074_firmware | — | cpe:2.3:o:qualcomm:qcn9074_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs405_firmware | — | cpe:2.3:o:qualcomm:qcs405_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs410_firmware | — | cpe:2.3:o:qualcomm:qcs410_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs605_firmware | — | cpe:2.3:o:qualcomm:qcs605_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs610_firmware | — | cpe:2.3:o:qualcomm:qcs610_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qrb5165_firmware | — | cpe:2.3:o:qualcomm:qrb5165_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qrb5165m_firmware | — | cpe:2.3:o:qualcomm:qrb5165m_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qrb5165n_firmware | — | cpe:2.3:o:qualcomm:qrb5165n_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6155p_firmware | — | cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8155p_firmware | — | cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8195p_firmware | — | cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd429_firmware | — | cpe:2.3:o:qualcomm:sd429_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd626_firmware | — | cpe:2.3:o:qualcomm:sd626_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd835_firmware | — | cpe:2.3:o:qualcomm:sd835_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm429w_firmware | — | cpe:2.3:o:qualcomm:sdm429w_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx20_firmware | — | cpe:2.3:o:qualcomm:sdx20_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx20m_firmware | — | cpe:2.3:o:qualcomm:sdx20m_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx24_firmware | — | cpe:2.3:o:qualcomm:sdx24_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx55_firmware | — | cpe:2.3:o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx65_firmware | — | cpe:2.3:o:qualcomm:sdx65_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9326_firmware | — | cpe:2.3:o:qualcomm:wcd9326_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9335_firmware | — | cpe:2.3:o:qualcomm:wcd9335_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9341_firmware | — | cpe:2.3:o:qualcomm:wcd9341_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9370_firmware | — | cpe:2.3:o:qualcomm:wcd9370_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9380_firmware | — | cpe:2.3:o:qualcomm:wcd9380_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcd9385_firmware | — | cpe:2.3:o:qualcomm:wcd9385_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3620_firmware | — | cpe:2.3:o:qualcomm:wcn3620_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3660b_firmware | — | cpe:2.3:o:qualcomm:wcn3660b_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3680b_firmware | — | cpe:2.3:o:qualcomm:wcn3680b_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3950_firmware | — | cpe:2.3:o:qualcomm:wcn3950_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3980_firmware | — | cpe:2.3:o:qualcomm:wcn3980_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3988_firmware | — | cpe:2.3:o:qualcomm:wcn3988_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3990_firmware | — | cpe:2.3:o:qualcomm:wcn3990_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn3998_firmware | — | cpe:2.3:o:qualcomm:wcn3998_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn6855_firmware | — | cpe:2.3:o:qualcomm:wcn6855_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wcn6856_firmware | — | cpe:2.3:o:qualcomm:wcn6856_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wsa8810_firmware | — | cpe:2.3:o:qualcomm:wsa8810_firmware:-:*:*:*:*:*:*:* |
| qualcomm | wsa8815_firmware | — | cpe:2.3:o:qualcomm:wsa8815_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.qualcomm.com/company/product-security/bulletins/february-2023-bulletin | Patch Vendor Advisory |