Vulnerability Description
Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Ar8035 Firmware | - |
| Qualcomm | Ar8035 | - |
| Qualcomm | Qca6391 Firmware | - |
| Qualcomm | Qca6391 | - |
| Qualcomm | Qca8081 Firmware | - |
| Qualcomm | Qca8081 | - |
| Qualcomm | Qca8337 Firmware | - |
| Qualcomm | Qca8337 | - |
| Qualcomm | Qca9984 Firmware | - |
| Qualcomm | Qca9984 | - |
| Qualcomm | Qcm2290 Firmware | - |
| Qualcomm | Qcm2290 | - |
| Qualcomm | Qcm4290 Firmware | - |
| Qualcomm | Qcm4290 | - |
| Qualcomm | Qcm6490 Firmware | - |
| Qualcomm | Qcm6490 | - |
| Qualcomm | Qcs2290 Firmware | - |
| Qualcomm | Qcs2290 | - |
| Qualcomm | Qcs405 Firmware | - |
| Qualcomm | Qcs405 | - |
References
- https://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletinVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletinVendor Advisory
FAQ
What is CVE-2021-30339?
CVE-2021-30339 is a vulnerability with a CVSS score of 9.0 (CRITICAL). Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wire...
How severe is CVE-2021-30339?
CVE-2021-30339 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-30339?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Ar8035 Firmware, Qualcomm Ar8035, Qualcomm Qca6391 Firmware, Qualcomm Qca6391, Qualcomm Qca8081 Firmware.