Reachable Assertion in Qualcomm products - CVE-2021-1982

 

Reachable Assertion in Qualcomm products - CVE-2021-1982

Published: November 3, 2021


Vulnerability identifier: #VU57906
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1982
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation of received NAS OTA message. A remote attacker can cause a denial of service condition on the target system.


Affected software

SM8450
WCD9385
WCD9380
WCD9375
WCD9371
WCD9370
WCD9360
WCD9341
SM8450P
WCN3910
SM7325
SM7250
SM6375
SM6250P
SM6250
SDXR2 5G
SDX65
SDX55M
WCN6851
WSA8835
WSA8830
WSA8815
WSA8810
WCN7851
WCN7850
WCN6856
WCN6855
WCN6850
WCN6750
WCN3998
WCN3991
WCN3990
WCN3988
WCN3980
WCN3950
QCA6595AU
QCX315
QCS6490
QCS610
QCS410
QCM6490
QCA8337
QCA8081
QCA6696
QSM8350
QCA6574A
QCA6436
QCA6431
QCA6426
QCA6421
QCA6391
QCA6390
SD750G
SD888 5G
SD870
SD865 5G
SD778G
SD768G
SD765G
SD765
AR8035
SD720G
SD690 5G
SD678
SD480
SD 675
SA515M
SDX55
QCA6574AU
SD855
SD730
SD675

How to mitigate CVE-2021-1982

Install updates from vendor's website.


External References

Related Security Bulletins