Improper Access Control in Snapdragon Products by Qualcomm
CVE-2021-1932
Key Information:
- Vendor
- Qualcomm
- Vendor
- CVE Published:
- 20 October 2021
Summary
A vulnerability exists in Qualcomm's Snapdragon products due to improper access control in a trusted application environment. This flaw could potentially allow unauthorized access to the CDSP or ADSP VM memory, impacting multiple Snapdragon product families including Automotive, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, and Wired Infrastructure and Networking. Attackers may exploit this vulnerability to gain unintended access, which poses significant risks to device integrity and data security.
Affected Version(s)
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking AQT1000, AR8035, QCA6390, QCA6420, QCA6430, QCA6574A, QCA6574AU, QCA6595, QCA6595AU, QCA6696, QCA9984, QCM2290, QCM4290, QCS2290, QCS405, QCS410, QCS4290, QCS610, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SD 675, SD 8C, SD 8CX, SD460, SD480, SD662, SD675, SD678, SD720G, SD730, SD7c, SD855, SD888 5G, SDM830, SDX24, SDX50M, SDX55, SDX55M, SM4125, SM6250, SM6250P, WCD9340, WCD9341, WCD9360, WCD9370, WCD9371, WCD9375, WCD9380, WCD9385, WCN3910, WCN3950, WCN3980, WCN3988, WCN3990, WCN3991, WCN3998, WCN3999, WCN6850, WHS9410, WSA8810, WSA8815
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved