SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-35070

RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile

MEDIUM 5.5EPSS 0.16%

Does this matter?

Lower severity and a low EPSS score (0.16%). Track it; it rarely justifies an emergency change on its own.

Description

RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.16% probability · 5th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
qualcomm/qcm6125 firmware · qualcomm/qcs6125 firmware · qualcomm/sd665 firmware · qualcomm/wcd9370 firmware · qualcomm/wcd9375 firmware · qualcomm/wcn3950 firmware · qualcomm/wcn3980 firmware · qualcomm/wsa8810 firmware · qualcomm/wsa8815 firmware
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.