SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-35079

Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

MEDIUM 5.5EPSS 0.13%

Does this matter?

Lower severity and a low EPSS score (0.13%). Track it; it rarely justifies an emergency change on its own.

Description

Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.13% probability · 3th percentile
CISA KEV
Not listed
Weakness
CWE-281
Affected
qualcomm/apq8053 firmware · qualcomm/aqt1000 firmware · qualcomm/msm8953 firmware · qualcomm/qca6390 firmware · qualcomm/qca6391 firmware · qualcomm/qca6420 firmware · qualcomm/qca6426 firmware · qualcomm/qca6430 firmware · qualcomm/qca6436 firmware · qualcomm/qcm4290 firmware · qualcomm/qcs4290 firmware · qualcomm/qcs603 firmware · qualcomm/qcs605 firmware · qualcomm/qualcomm215 firmware · qualcomm/sd460 firmware · qualcomm/sd480 firmware · qualcomm/sd662 firmware · qualcomm/sd680 firmware · qualcomm/sd690 5g firmware · qualcomm/sd695 firmware · +40 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.