Improper access control in Qualcomm products - CVE-2021-30314

 

Improper access control in Qualcomm products - CVE-2021-30314

Published: January 4, 2022


Vulnerability identifier: #VU59187
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30314
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a malicious application to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in Telephony component. A malicious third party application can access the Telephony service and obtain sensitive information.


Affected software

SM6225
WCD9385
WCD9380
WCD9375
WCD9370
WCD9341
SM7325P
SM7315
SM7250P
SM6375
WCN3610
SDXR25G
SDX55M
SDA429W
SD8885G
SD870
SD8655G
SD780G
WCN6750
WSA8835
WSA8830
WSA8815
WSA8810
WCN6856
WCN6855
WCN6851
WCN6850
SD778G
WCN6740
WCN3998
WCN3991
WCN3990
WCN3988
WCN3980
WCN3950
WCN3910
QCM2290
Qualcomm215
QCS6490
QCS610
QCS603
QCS4290
QCS2290
QCM6490
QCM4290
SA6145P
QCA6696
QCA6595AU
QCA6574A
QCA6574
QCA6436
QCA6426
QCA6391
SD768G
SD765G
SD765
SD662
SD480
SD460
QCA6390
SD8Gen15G
SA8155P
SA8155
SA8150P
SA8145P
SA6155
SA6150P
Pixel
SD888
QCS605
QCA6574AU
SD205
SD665
SD210
SA6155P

How to mitigate CVE-2021-30314

Install updates from vendor's website.

Pixel - update to 2022-01-05

External References

Related Security Bulletins