Information disclosure in Qualcomm products - CVE-2021-35080

 

Information disclosure in Qualcomm products - CVE-2021-35080

Published: May 12, 2022 / Updated: May 12, 2022


Vulnerability identifier: #VU63108
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35080
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local appliction to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in KERNEL component. A local appliction can gain unauthorized access to sensitive information on the system.


Affected software

WCD9370
WSA8835
WSA8830
WSA8815
WSA8810
WCN3998
WCN3991
WCN3988
WCN3980
WCN3950
WCN3910
WCD9385
WCD9375
QCM2290
SW5100P
SW5100
SM4125
SD695
SD680
SD662
SD480
SD460
QCS4290
QCS2290
QCM4290

How to mitigate CVE-2021-35080

Install updates from vendor's website.


External References

Related Security Bulletins