Insecure configuration in Qualcomm products - CVE-2021-1896

 

Insecure configuration in Qualcomm products - CVE-2021-1896

Published: July 5, 2021


Vulnerability identifier: #VU54548
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1896
CWE-ID: CWE-16
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to weak configuration in WLAN, which can cause forwarding of unencrypted packets from one client to another. A remote attacker on the local network can intercept traffic and gain access to sensitive information.


Affected software

SD7c
WSA8815
WSA8810
WCN6850
WCN3998
WCN3991
WCN3990
WCD9341
WCD9340
SM6250
AQT1000
SD8CX
SD8C
SC8180X+SDX55
QCA6430
QCA6420
QCA6174
QCA6164
SD850
QCA9377
QCA6174A

How to mitigate CVE-2021-1896

Install updates from vendor's website.


External References

Related Security Bulletins