Information disclosure in Qualcomm products - CVE-2021-35080
Published: May 12, 2022 / Updated: May 12, 2022
Vulnerability identifier: #VU63108
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-35080
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local appliction to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in KERNEL component. A local appliction can gain unauthorized access to sensitive information on the system.
Affected software
WCD9370
WSA8835
WSA8830
WSA8815
WSA8810
WCN3998
WCN3991
WCN3988
WCN3980
WCN3950
WCN3910
WCD9385
WCD9375
QCM2290
SW5100P
SW5100
SM4125
SD695
SD680
SD662
SD480
SD460
QCS4290
QCS2290
QCM4290
WSA8835
WSA8830
WSA8815
WSA8810
WCN3998
WCN3991
WCN3988
WCN3980
WCN3950
WCN3910
WCD9385
WCD9375
QCM2290
SW5100P
SW5100
SM4125
SD695
SD680
SD662
SD480
SD460
QCS4290
QCS2290
QCM4290
How to mitigate CVE-2021-35080
Install updates from vendor's website.