First published: Fri Sep 02 2022(Updated: )
Improper checking of AP-S lock bit while verifying the secure resource group permissions can lead to non secure read and write access in Snapdragon Connectivity, Snapdragon Mobile
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm Snapdragon 8 Gen 1 Firmware | ||
Qualcomm SM8475P | ||
Qualcomm SM7450 Firmware | ||
Qualcomm SM7450 Firmware | ||
Qualcomm SM8475P Firmware | ||
Qualcomm SM8475P | ||
Qualcomm SM8475P Firmware | ||
Qualcomm WCD9370 Firmware | ||
Qualcomm WCD9370 Firmware | ||
Qualcomm WCD9375 | ||
Qualcomm WCD9375 Firmware | ||
Qualcomm WCD9380 | ||
Qualcomm WCD9380 Firmware | ||
Qualcomm WCD9385 | ||
Qualcomm WCD9385 Firmware | ||
qualcomm wcn6750 firmware | ||
qualcomm wcn6750 firmware | ||
Qualcomm WCN6855 Firmware | ||
Qualcomm WCN6855 Firmware | ||
Qualcomm WCN6856 Firmware | ||
Qualcomm WCN6856 | ||
Qualcomm WCN7851 | ||
Qualcomm WCN7851 Firmware | ||
Qualcomm WSA8830 | ||
Qualcomm WSA8830 | ||
Qualcomm WSA8832 | ||
qualcomm wsa8832 firmware | ||
Qualcomm WSA8835 | ||
Qualcomm WSA8835 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35108 is a vulnerability that occurs due to improper checking of AP-S lock bit while verifying the secure resource group permissions, which can lead to non-secure read and write access in Snapdragon Connectivity and Snapdragon Mobile.
CVE-2021-35108 affects the affected software by allowing non-secure read and write access in Snapdragon Connectivity and Snapdragon Mobile.
The severity of CVE-2021-35108 is high, with a severity value of 6.8.
To fix CVE-2021-35108, apply the necessary patches and updates provided by Qualcomm and follow the recommendations provided in the official bulletins.
You can find more information about CVE-2021-35108 in the official bulletins provided by Qualcomm and the Android Security Bulletin.