First published: Wed Apr 07 2021(Updated: )
Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Wired Infrastructure and Networking
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm AQT1000 Firmware | ||
Qualcomm AQT1000 Firmware | ||
Qualcomm pm8005 firmware | ||
Qualcomm pm8005 firmware | ||
Qualcomm pm855 firmware | ||
Qualcomm PM855P | ||
Qualcomm pm855 firmware | ||
Qualcomm PM855P | ||
Qualcomm 8998 Firmware | ||
Qualcomm 8998 | ||
Qualcomm 8998 Firmware | ||
Qualcomm PMI8998 | ||
Qualcomm QAT3550 Firmware | ||
Qualcomm QAT3550 Firmware | ||
qualcomm qca1062 Firmware | ||
Qualcomm QCA1062 | ||
Qualcomm QCA1064 | ||
qualcomm qca1064 Firmware | ||
qualcomm qca2066 Firmware | ||
Qualcomm QCA2066 | ||
Qualcomm QCA6164 Firmware | ||
Qualcomm QCA6164 Firmware | ||
Qualcomm QCA6174 Firmware | ||
Qualcomm QCA6174A | ||
Qualcomm QCA6174A Firmware | ||
Qualcomm QCA6174A Firmware | ||
Qualcomm QCA6310 Firmware | ||
Qualcomm QCA6310 Firmware | ||
Qualcomm QCA6335 Firmware | ||
Qualcomm QCA6335 Firmware | ||
Qualcomm QCA6391 Firmware | ||
Qualcomm QCA6391 Firmware | ||
Qualcomm QCA6420 Firmware | ||
Qualcomm QCA6420 Firmware | ||
Qualcomm QCA6430 firmware | ||
Qualcomm QCA6430 firmware | ||
Qualcomm QCA6595AU Firmware | ||
Qualcomm QCA6595AU Firmware | ||
Qualcomm QCA9377 Firmware | ||
Qualcomm QCA9377 Firmware | ||
Qualcomm QCN7605 Firmware | ||
Qualcomm QCN7605 Firmware | ||
Qualcomm QCN7606W Firmware | ||
qualcomm qcn7606 Firmware | ||
Qualcomm QET4100 | ||
Qualcomm QET4100 Firmware | ||
Qualcomm QFE2081FC | ||
Qualcomm QFE2081FC | ||
qualcomm qfe2082fc | ||
qualcomm qfe2082fc firmware | ||
Qualcomm QFE3100 Firmware | ||
Qualcomm QFE3100 Firmware | ||
Qualcomm QFE3440FC Firmware | ||
Qualcomm QFE3440FC Firmware | ||
Qualcomm QFE4455FC | ||
Qualcomm QFE4455FC | ||
Qualcomm QLN1035BD | ||
Qualcomm QLN1035BD Firmware | ||
Qualcomm SD 8C Firmware | ||
Qualcomm SD 8C Firmware | ||
Qualcomm SD 8cx Firmware | ||
Qualcomm Snapdragon 8cx | ||
Qualcomm Snapdragon 835 | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SD 845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm SD850 Firmware | ||
Qualcomm SDR8150 Firmware | ||
Qualcomm SDR8150 Firmware | ||
Qualcomm SMB1350 | ||
Qualcomm SMB1350 Firmware | ||
Qualcomm SMB1351 | ||
Qualcomm SMB1351 Firmware | ||
Qualcomm SMB1380 Firmware | ||
Qualcomm SMB1380 Firmware | ||
Qualcomm SMB1381 Firmware | ||
Qualcomm SMB1381 Firmware | ||
Qualcomm SMB1390 | ||
Qualcomm SMB1390 Firmware | ||
Qualcomm SMB2351 | ||
Qualcomm SMB2351 Firmware | ||
Qualcomm WCD9335 Firmware | ||
Qualcomm WCD9335 Firmware | ||
Qualcomm WCD9340 Firmware | ||
Qualcomm WCD9340 Firmware | ||
Qualcomm WCD9341 | ||
Qualcomm WCD9341 Firmware | ||
Qualcomm WCN3990 | ||
Qualcomm WCN3990 | ||
Qualcomm wcn3998 firmware | ||
Qualcomm wcn3998 firmware | ||
Qualcomm WCN6850 Firmware | ||
Qualcomm WCN6850 Firmware | ||
Qualcomm WCN6851 Firmware | ||
Qualcomm WCN6851 Firmware | ||
Qualcomm WCN6855 Firmware | ||
Qualcomm WCN6855 Firmware | ||
Qualcomm WCN6856 Firmware | ||
Qualcomm WCN6856 | ||
Qualcomm WGR7640 | ||
Qualcomm WGR7640 Firmware | ||
Qualcomm WSA8810 | ||
Qualcomm WSA8810 Firmware | ||
qualcomm wsa8815 firmware | ||
qualcomm wsa8815 firmware | ||
Qualcomm WTR5975 | ||
Qualcomm WTR5975 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1892 is categorized as a high severity vulnerability due to memory corruption that could allow an attacker to execute arbitrary code.
To fix CVE-2021-1892, it is recommended to update the affected Qualcomm firmware to the latest version provided by Qualcomm.
CVE-2021-1892 affects various Qualcomm devices including the aqt1000 and Pm8005 firmware among others.
CVE-2021-1892 is a memory corruption vulnerability caused by improper input validation in several Qualcomm firmware components.
Yes, CVE-2021-1892 may be exploited remotely if an attacker can send malicious IO control commands to the vulnerable devices.