First published: Mon Apr 04 2022(Updated: )
Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm AR8035 Firmware | ||
Qualcomm AR8035 Firmware | ||
Qualcomm QCA6391 Firmware | ||
Qualcomm QCA6391 Firmware | ||
Qualcomm QCA8081 firmware | ||
Qualcomm QCA8081 firmware | ||
Qualcomm QCA8337 Firmware | ||
Qualcomm QCA8337 Firmware | ||
Qualcomm QCA9984 Firmware | ||
qualcomm qca9984 firmware | ||
Qualcomm QCM2290 | ||
Qualcomm QCM2290 Firmware | ||
Qualcomm QCM4290 | ||
Qualcomm QCM4290 Firmware | ||
Qualcomm QCM6490 | ||
Qualcomm QCM6490 Firmware | ||
Qualcomm QCS2290 | ||
Qualcomm QCS2290 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS4290 Firmware | ||
Qualcomm QCS4290 Firmware | ||
Qualcomm QCS6490 Firmware | ||
Qualcomm QCS6490 Firmware | ||
Qualcomm Snapdragon 8 Gen 1 Firmware | ||
Qualcomm SM8475P | ||
Qualcomm SD460 Firmware | ||
Qualcomm SD460 Firmware | ||
Qualcomm SD 480 Firmware | ||
Qualcomm Snapdragon 480 | ||
Qualcomm SD662 Firmware | ||
Qualcomm SD662 Firmware | ||
Qualcomm SD680 Firmware | ||
Qualcomm SD680 Firmware | ||
Qualcomm Snapdragon 690 5G Firmware | ||
Qualcomm Snapdragon 690 5G Firmware | ||
Qualcomm SD750G Firmware | ||
Qualcomm Snapdragon 750G | ||
Qualcomm SD765 Firmware | ||
Qualcomm Snapdragon 765 | ||
Qualcomm SD765 Firmware | ||
Qualcomm Snapdragon 765G | ||
Qualcomm SD768 Firmware | ||
Qualcomm SD768G Firmware | ||
Qualcomm SD778G Firmware | ||
Qualcomm Snapdragon 778G | ||
Qualcomm Snapdragon 780G Firmware | ||
Qualcomm Snapdragon 780G | ||
Qualcomm Snapdragon 888 Firmware | ||
Qualcomm Snapdragon 888 Firmware | ||
Qualcomm Snapdragon 888 5G Firmware | ||
Qualcomm Snapdragon 888 5G | ||
Qualcomm SDX57M | ||
Qualcomm SDX57M Firmware | ||
Qualcomm SDX65 | ||
Qualcomm SDX65M | ||
Qualcomm SM6375 Firmware | ||
Qualcomm SM6375 Firmware | ||
Qualcomm SM7250 Firmware | ||
Qualcomm SM7250 | ||
Qualcomm SM7315 | ||
Qualcomm SM7315 Firmware | ||
Qualcomm SM7325P Firmware | ||
Qualcomm SM7325P Firmware | ||
Qualcomm SW5100P | ||
Qualcomm SW5100P | ||
Qualcomm SW5100 Firmware | ||
Qualcomm SW5100 Firmware | ||
Qualcomm WCD9370 Firmware | ||
Qualcomm WCD9370 Firmware | ||
Qualcomm WCD9375 | ||
Qualcomm WCD9375 Firmware | ||
Qualcomm WCD9380 | ||
Qualcomm WCD9380 Firmware | ||
Qualcomm WCD9385 | ||
Qualcomm WCD9385 Firmware | ||
Qualcomm WCN3910 Firmware | ||
Qualcomm WCN3910 Firmware | ||
Qualcomm WCN3950 Firmware | ||
Qualcomm WCN3950 Firmware | ||
Qualcomm Wcn3980 | ||
Qualcomm WCN3980 | ||
Qualcomm WCN3988 Firmware | ||
Qualcomm WCN3988 Firmware | ||
Qualcomm WCN3991 Firmware | ||
Qualcomm WCN3991 Firmware | ||
Qualcomm WCN3998 Firmware | ||
Qualcomm wcn3998 firmware | ||
Qualcomm WCN3999 Firmware | ||
Qualcomm WCN3999 Firmware | ||
Qualcomm WCN6740 Firmware | ||
Qualcomm WCN6740 Firmware | ||
Qualcomm WCN6750 Firmware | ||
Qualcomm WCN6750 Firmware | ||
Qualcomm WCN6850 Firmware | ||
Qualcomm WCN6850 Firmware | ||
Qualcomm WCN6851 Firmware | ||
Qualcomm WCN6851 Firmware | ||
Qualcomm WCN6855 Firmware | ||
Qualcomm WCN6855 Firmware | ||
Qualcomm WCN6856 Firmware | ||
Qualcomm WCN6856 Firmware | ||
Qualcomm WSA8810 | ||
Qualcomm WSA8810 Firmware | ||
Qualcomm WSA8815 Firmware | ||
Qualcomm WSA8815 Firmware | ||
Qualcomm WSA8830 | ||
Qualcomm WSA8830 | ||
Qualcomm WSA8835 | ||
Qualcomm WSA8835 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30339 has a high severity due to its potential to lead to improper key generation.
To fix CVE-2021-30339, ensure that your affected Qualcomm devices are updated with the latest firmware that addresses this vulnerability.
CVE-2021-30339 affects various Qualcomm products including Snapdragon Connectivity, Snapdragon Mobile, and multiple firmware versions.
CVE-2021-30339 could allow attackers to exploit improper key generation, potentially compromising the security of communications.
At the time of disclosure, there was no evidence suggesting that CVE-2021-30339 was actively being exploited in the wild.