Information disclosure in Qualcomm products - CVE-2021-1918

 

Information disclosure in Qualcomm products - CVE-2021-1918

Published: December 7, 2021


Vulnerability identifier: #VU58567
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1918
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in Kernel. A local user can gain unauthorized access to sensitive information on the system.


Affected software

WCD9375
WSA8835
WSA8830
WSA8815
WSA8810
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
WCN3998
WCN3991
WCN3988
WCD9385
WCD9380
QCA6391
WCD9370
SM7325P
SM7250P
SD888 5G
SD778G
SD768G
SD765G
SD765
SD750G
SD690 5G
QRB5165N
QRB5165
QCS6490
QCM6490

How to mitigate CVE-2021-1918

Install updates from vendor's website.


External References

Related Security Bulletins