#VU60358 Improper Authentication in Qualcomm products - CVE-2021-30317
Published: February 8, 2022 / Updated: February 6, 2023
Vulnerability identifier: #VU60358
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-30317
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
WCN3950
WCN3980
WCN3988
WCN3990
WCN3991
WCN3998
WCN3999
WCN6750
WCN6850
WCN6851
WCN6855
WSA8810
WSA8815
WSA8830
WSA8835
WCN3950
WCN3980
WCN3988
WCN3990
WCN3991
WCN3998
WCN3999
WCN6750
WCN6850
WCN6851
WCN6855
WSA8810
WSA8815
WSA8830
WSA8835
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a malicious application to elevate privileges on the system.
The vulnerability exists due to improper validation of program headers containing ELF metadata. A malicious application can bypass image verification and execute arbitrary code on the system with elevated privileges.
Remediation
Install updates from vendor's website.