First published: Tue Jun 14 2022(Updated: )
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
Qualcomm QCA9367 Firmware | ||
Qualcomm QCA9367 Firmware | ||
Qualcomm QCA9377 Firmware | ||
Qualcomm QCA9377 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35082 has a medium severity rating due to the potential for a race condition affecting PDCP and RRC tasks.
To mitigate CVE-2021-35082, ensure that you update to the latest firmware version provided by Qualcomm for your device.
CVE-2021-35082 affects Qualcomm Mdm9206 and various QCA9367 and QCA9377 firmware products.
Exploitation of CVE-2021-35082 could potentially allow an attacker to interfere with RRC security mode operations.
CVE-2021-35082 could potentially be exploited under certain conditions, allowing an attacker to affect communications over the affected devices.