CVE-2021-35071
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile,…
Does this matter?
Lower severity and a low EPSS score (0.13%). Track it; it rarely justifies an emergency change on its own.
Description
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- qualcomm/aqt1000 firmware · qualcomm/ar8035 firmware · qualcomm/ar9380 firmware · qualcomm/csr8811 firmware · qualcomm/csrb31024 firmware · qualcomm/fsm10055 firmware · qualcomm/fsm10056 firmware · qualcomm/ipq4018 firmware · qualcomm/ipq4019 firmware · qualcomm/ipq4028 firmware · qualcomm/ipq4029 firmware · qualcomm/ipq5010 firmware · qualcomm/ipq5018 firmware · qualcomm/ipq5028 firmware · qualcomm/ipq6000 firmware · qualcomm/ipq6010 firmware · qualcomm/ipq6018 firmware · qualcomm/ipq6028 firmware · qualcomm/ipq8064 firmware · qualcomm/ipq8065 firmware · +40 more
- Source
- product-security@qualcomm.com
References
- https://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletinPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.