Detection of Error Condition Without Action in Qualcomm products - CVE-2021-30283
Published: December 7, 2021
Vulnerability identifier: #VU58578
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30283
CWE-ID:
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of debug register trap from user applications. A local attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
WCD9375
WSA8835
WSA8830
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
WCD9385
WCD9380
QCA6391
WCD9370
SM7325P
SD888 5G
SD778G
QRB5165N
QRB5165
QCS6490
QCM6490
WSA8835
WSA8830
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
WCD9385
WCD9380
QCA6391
WCD9370
SM7325P
SD888 5G
SD778G
QRB5165N
QRB5165
QCS6490
QCM6490
How to mitigate CVE-2021-30283
Install updates from vendor's website.