CVE-2021-30325
Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…
Does this matter?
Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.
Description
Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-129
- Affected
- qualcomm/apq8096au firmware · qualcomm/ar8031 firmware · qualcomm/ar8035 firmware · qualcomm/ar9380 firmware · qualcomm/csr8811 firmware · qualcomm/csra6620 firmware · qualcomm/csra6640 firmware · qualcomm/ipq4018 firmware · qualcomm/ipq4019 firmware · qualcomm/ipq4028 firmware · qualcomm/ipq4029 firmware · qualcomm/ipq5010 firmware · qualcomm/ipq5018 firmware · qualcomm/ipq5028 firmware · qualcomm/ipq6000 firmware · qualcomm/ipq6005 firmware · qualcomm/ipq6010 firmware · qualcomm/ipq6018 firmware · qualcomm/ipq6028 firmware · qualcomm/ipq8064 firmware · +40 more
- Source
- product-security@qualcomm.com
References
- https://www.qualcomm.com/company/product-security/bulletins/february-2022-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/february-2022-bulletinPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.