MEDIUM · 5.5

CVE-2021-30331

Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdrag...

Vulnerability Description

Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
QualcommAr8035 Firmware-
QualcommAr8035-
QualcommFsm10055 Firmware-
QualcommFsm10055-
QualcommFsm10056 Firmware-
QualcommFsm10056-
QualcommMdm9150 Firmware-
QualcommMdm9150-
QualcommMdm9650 Firmware-
QualcommMdm9650-
QualcommQca6174A Firmware-
QualcommQca6174A-
QualcommQca6390 Firmware-
QualcommQca6390-
QualcommQca6391 Firmware-
QualcommQca6391-
QualcommQca6426 Firmware-
QualcommQca6426-
QualcommQca6436 Firmware-
QualcommQca6436-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-30331?

CVE-2021-30331 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdrag...

How severe is CVE-2021-30331?

CVE-2021-30331 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-30331?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Ar8035 Firmware, Qualcomm Ar8035, Qualcomm Fsm10055 Firmware, Qualcomm Fsm10055, Qualcomm Fsm10056 Firmware.