#VU58567 Information disclosure in Qualcomm products - CVE-2021-1918

 

#VU58567 Information disclosure in Qualcomm products - CVE-2021-1918

Published: December 7, 2021


Vulnerability identifier: #VU58567
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-1918
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
QCA6391
QCM6490
QCS6490
QRB5165
QRB5165N
SD690 5G
SD750G
SD765
SD765G
SD768G
SD778G
SD888 5G
SM7250P
SM7325P
WCD9370
WCD9375
WCD9380
WCD9385
WCN3988
WCN3991
WCN3998
WCN6750
WCN6850
WCN6851
WCN6855
WCN6856
WSA8810
WSA8815
WSA8830
WSA8835
Software vendor:
Qualcomm

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in Kernel. A local user can gain unauthorized access to sensitive information on the system.


Remediation

Install updates from vendor's website.

External links