Improper Authentication in Qualcomm products - CVE-2021-30317

 

Improper Authentication in Qualcomm products - CVE-2021-30317

Published: February 8, 2022 / Updated: February 6, 2023


Vulnerability identifier: #VU60358
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30317
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a malicious application to elevate privileges on the system.

The vulnerability exists due to improper validation of program headers containing ELF metadata. A malicious application can bypass image verification and execute arbitrary code on the system with elevated privileges.


Affected software

WCN3950
WCN3980
WCN3988
WCN3990
WCN3991
WCN3998
WCN3999
WCN6750
WCN6850
WCN6851
WCN6855
WSA8810
WSA8815
WSA8830
WSA8835

How to mitigate CVE-2021-30317

Install updates from vendor's website.


External References

Related Security Bulletins