Buffer overflow in Qualcomm products - CVE-2021-1962
Published: September 6, 2021
Vulnerability identifier: #VU56339
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1962
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error while processing IOCTL for getting peripheral endpoint information within the Data Network Stack & Connectivity component. A local user can execute arbitrary code with elevated privileges.
Affected software
SD205
SDX55
SD855
SD730
SD665
SD210
SD675
SA6155P
QCA9558
QCA9531
QCA6574AU
MDM9150
IPQ8064
QCA9980
QCS605
SDX55M
SDX50M
SDA429W
SD720G
SD678
SM6250
SA8195P
SA8155P
SA8155
SA8150P
SA8145P
SA6155
SA6150P
WCN3620
WSA8815
WSA8810
WCN3998
WCN3991
WCN3990
WCN3988
WCN3980
WCN3950
WCN3680
WCN3660B
SA6145P
WCN3615
WCN3610
WCD9380
WCD9375
WCD9370
WCD9341
WCD9340
WCD9335
WCD9326
QCA6420
QCA6696
QCA6595AU
QCA6595
QCA6584AU
QCA6574A
QCA6574
QCA6430
QCA9561
QCA6391
IPQ8069
IPQ8068
IPQ8065
FSM10056
FSM10055
AR9380
Qualcomm215
QCS610
QCS410
QCA9994
QCA9992
QCA9990
QCA9984
QCA9982
AQT1000
QCA9898
QCA9896
QCA9889
QCA9888
QCA9887
QCA9886
QCA9882
QCA9880
QCA9563
SDX55
SD855
SD730
SD665
SD210
SD675
SA6155P
QCA9558
QCA9531
QCA6574AU
MDM9150
IPQ8064
QCA9980
QCS605
SDX55M
SDX50M
SDA429W
SD720G
SD678
SM6250
SA8195P
SA8155P
SA8155
SA8150P
SA8145P
SA6155
SA6150P
WCN3620
WSA8815
WSA8810
WCN3998
WCN3991
WCN3990
WCN3988
WCN3980
WCN3950
WCN3680
WCN3660B
SA6145P
WCN3615
WCN3610
WCD9380
WCD9375
WCD9370
WCD9341
WCD9340
WCD9335
WCD9326
QCA6420
QCA6696
QCA6595AU
QCA6595
QCA6584AU
QCA6574A
QCA6574
QCA6430
QCA9561
QCA6391
IPQ8069
IPQ8068
IPQ8065
FSM10056
FSM10055
AR9380
Qualcomm215
QCS610
QCS410
QCA9994
QCA9992
QCA9990
QCA9984
QCA9982
AQT1000
QCA9898
QCA9896
QCA9889
QCA9888
QCA9887
QCA9886
QCA9882
QCA9880
QCA9563
How to mitigate CVE-2021-1962
Install updates from vendor's website.