8.4

CVE-2021-35126

Memory corruption in DSP service due to improper validation of input parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

Data is provided by the National Vulnerability Database (NVD)
QualcommQam8295p Firmware Version-
   QualcommQam8295p Version-
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
QualcommQca6696 Firmware Version-
   QualcommQca6696 Version-
QualcommQcm6490 Firmware Version-
   QualcommQcm6490 Version-
QualcommQcs6490 Firmware Version-
   QualcommQcs6490 Version-
QualcommSa8295p Firmware Version-
   QualcommSa8295p Version-
QualcommSd 8 Gen1 5g Firmware Version-
   QualcommSm8475 Version-
QualcommSd 8cx Gen3 Firmware Version-
   QualcommSd 8cx Gen3 Version-
QualcommSd778g Firmware Version-
   QualcommSd778g Version-
QualcommSd780g Firmware Version-
   QualcommSd780g Version-
QualcommSd888 Firmware Version-
   QualcommSd888 Version-
QualcommSd888 5g Firmware Version-
   QualcommSd888 5g Version-
QualcommSm7315 Firmware Version-
   QualcommSm7315 Version-
QualcommSm7325p Firmware Version-
   QualcommSm7325p Version-
QualcommWcd9370 Firmware Version-
   QualcommWcd9370 Version-
QualcommWcd9375 Firmware Version-
   QualcommWcd9375 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcn6740 Firmware Version-
   QualcommWcn6740 Version-
QualcommWcn6750 Firmware Version-
   QualcommWcn6750 Version-
QualcommWcn6850 Firmware Version-
   QualcommWcn6850 Version-
QualcommWcn6851 Firmware Version-
   QualcommWcn6851 Version-
QualcommWcn6855 Firmware Version-
   QualcommWcn6855 Version-
QualcommWcn6856 Firmware Version-
   QualcommWcn6856 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.302
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
product-security@qualcomm.com 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-129 Improper Validation of Array Index

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.