MEDIUM · 6.5

CVE-2021-1918

Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

Vulnerability Description

Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
QualcommQca6391 Firmware-
QualcommQca6391-
QualcommQcm6490 Firmware-
QualcommQcm6490-
QualcommQcs6490 Firmware-
QualcommQcs6490-
QualcommQrb5165 Firmware-
QualcommQrb5165-
QualcommQrb5165N Firmware-
QualcommQrb5165N-
QualcommSd690 5G Firmware-
QualcommSd690 5G-
QualcommSd750G Firmware-
QualcommSd750G-
QualcommSd765 Firmware-
QualcommSd765-
QualcommSd765G Firmware-
QualcommSd765G-
QualcommSd768G Firmware-
QualcommSd768G-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-1918?

CVE-2021-1918 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

How severe is CVE-2021-1918?

CVE-2021-1918 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-1918?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Qca6391 Firmware, Qualcomm Qca6391, Qualcomm Qcm6490 Firmware, Qualcomm Qcm6490, Qualcomm Qcs6490 Firmware.