Information disclosure in Qualcomm products - CVE-2021-30331

 

Information disclosure in Qualcomm products - CVE-2021-30331

Published: March 7, 2022


Vulnerability identifier: #VU61061
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-30331
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in Data Modem. A local application can send a specially crafted external command via DIAG interface and gain unauthorized access to sensitive information on the system.


Affected software

SM6250
WCD9370
WCD9341
WCD9335
SW5100P
SW5100
SM7325P
SM7250P
SM6375
SM6250P
WCD9375
SM6225
SDXR25G
SDX65
SDX55M
SD8885G
SD870
SD8655G
WCN3998
WSA8835
WSA8830
WSA8815
WSA8810
WCN6856
WCN6855
WCN6851
WCN6850
WCN6750
SD778G
WCN3991
WCN3990
WCN3988
WCN3980
WCN3950
WCN3910
WCD9385
WCD9380
QCA6436
QCS410
QCS2290
QCM6490
QCM6125
QCM4290
QCM2290
QCA8337
QCA8081
QCS4290
QCA6426
QCA6391
QCA6390
FSM10056
FSM10055
SD662
SD768G
SD765G
SD765
SD750G
SD720G
SD6905G
SD678
AR8035
SD480
SD460
SD8Gen15G
QCX315
QCS6490
QCS6125
QCS610
Pixel
SDX55
QCA9377
QCA6174A
MDM9650
MDM9150
SD730
SD665
SD675

How to mitigate CVE-2021-30331

Install updates from vendor's website.

Pixel - update to 2022-03-05

External References

Related Security Bulletins