| |
Vulnerability CVE-2021-30331
Published: 2022-04-01
| Description: |
Possible buffer overflow due to improper data validation of external commands sent via DIAG interface in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables |
Type:
CWE-120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'))
CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)
| CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
2.1/10 |
2.9/10 |
3.9/10 |
| Exploit range |
Attack complexity |
Authentication |
Local |
Low |
No required |
| Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://www.qualcomm.com/company/product-security/bulletins/march-2022-bulletin
|
|
|
closedb();
?>
Copyright 2026, cxsecurity.com
|
|
|