Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-30327


Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon Voice & Music


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.5, with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and limited availability for affected systems. Impacting 158 products from qualcomm, from qualcomm, from qualcomm and 155 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2022, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2022-06-14T10:15:14.593

Last Modified

2024-11-21T06:03:50.327

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm apq8097_firmware - Yes
Hardware qualcomm apq8097 - No
Operating System qualcomm apq8098_firmware - Yes
Hardware qualcomm apq8098 - No
Operating System qualcomm ipq6000_firmware - Yes
Hardware qualcomm ipq6000 - No
Operating System qualcomm ipq6005_firmware - Yes
Hardware qualcomm ipq6005 - No
Operating System qualcomm ipq6010_firmware - Yes
Hardware qualcomm ipq6010 - No
Operating System qualcomm ipq6018_firmware - Yes
Hardware qualcomm ipq6018 - No
Operating System qualcomm ipq6028_firmware - Yes
Hardware qualcomm ipq6028 - No
Operating System qualcomm mdm9205_firmware - Yes
Hardware qualcomm mdm9205 - No
Operating System qualcomm msm8997_firmware - Yes
Hardware qualcomm msm8997 - No
Operating System qualcomm msm8998_firmware - Yes
Hardware qualcomm msm8998 - No
Operating System qualcomm qca6595_firmware - Yes
Hardware qualcomm qca6595 - No
Operating System qualcomm qca6595au_firmware - Yes
Hardware qualcomm qca6595au - No
Operating System qualcomm qcn7605_firmware - Yes
Hardware qualcomm qcn7605 - No
Operating System qualcomm qcn7605w_firmware - Yes
Hardware qualcomm qcn7605w - No
Operating System qualcomm qcn7606_firmware - Yes
Hardware qualcomm qcn7606 - No
Operating System qualcomm qcn7606w_firmware - Yes
Hardware qualcomm qcn7606w - No
Operating System qualcomm qcs401_firmware - Yes
Hardware qualcomm qcs401 - No
Operating System qualcomm qcs402_firmware - Yes
Hardware qualcomm qcs402 - No
Operating System qualcomm qcs403_firmware - Yes
Hardware qualcomm qcs403 - No
Operating System qualcomm qcs404_firmware - Yes
Hardware qualcomm qcs404 - No
Operating System qualcomm qcs405_firmware - Yes
Hardware qualcomm qcs405 - No
Operating System qualcomm qcs407_firmware - Yes
Hardware qualcomm qcs407 - No
Operating System qualcomm sa2145p_firmware - Yes
Hardware qualcomm sa2145p - No
Operating System qualcomm sa2150p_firmware - Yes
Hardware qualcomm sa2150p - No
Operating System qualcomm sa4150p_firmware - Yes
Hardware qualcomm sa4150p - No
Operating System qualcomm sa4155p_firmware - Yes
Hardware qualcomm sa4155p - No
Operating System qualcomm sa415m_firmware - Yes
Hardware qualcomm sa415m - No
Operating System qualcomm sa4250p_firmware - Yes
Hardware qualcomm sa4250p - No
Operating System qualcomm sa515m_firmware - Yes
Hardware qualcomm sa515m - No
Operating System qualcomm sa6115_firmware - Yes
Hardware qualcomm sa6115 - No
Operating System qualcomm sa6115p_firmware - Yes
Hardware qualcomm sa6115p - No
Operating System qualcomm sa6125_firmware - Yes
Hardware qualcomm sa6125 - No
Operating System qualcomm sa6125p_firmware - Yes
Hardware qualcomm sa6125p - No
Operating System qualcomm sa6145_firmware - Yes
Hardware qualcomm sa6145 - No
Operating System qualcomm sa6145p_firmware - Yes
Hardware qualcomm sa6145p - No
Operating System qualcomm sa615x_firmware - Yes
Hardware qualcomm sa615x - No
Operating System qualcomm sa615xp_firmware - Yes
Hardware qualcomm sa615xp - No
Operating System qualcomm sa8150p_firmware - Yes
Hardware qualcomm sa8150p - No
Operating System qualcomm sa8155_firmware - Yes
Hardware qualcomm sa8155 - No
Operating System qualcomm sa8155p_firmware - Yes
Hardware qualcomm sa8155p - No
Operating System qualcomm sa8195p_firmware - Yes
Hardware qualcomm sa8195p - No
Operating System qualcomm sc7180_firmware - Yes
Hardware qualcomm sc7180 - No
Operating System qualcomm sc7180p_firmware - Yes
Hardware qualcomm sc7180p - No
Operating System qualcomm sc8180x_firmware - Yes
Hardware qualcomm sc8180x - No
Operating System qualcomm sc8180xp_firmware - Yes
Hardware qualcomm sc8180xp - No
Operating System qualcomm sda658_firmware - Yes
Hardware qualcomm sda658 - No
Operating System qualcomm sda660_firmware - Yes
Hardware qualcomm sda660 - No
Operating System qualcomm sda670_firmware - Yes
Hardware qualcomm sda670 - No
Operating System qualcomm sda830_firmware - Yes
Hardware qualcomm sda830 - No
Operating System qualcomm sda845_firmware - Yes
Hardware qualcomm sda845 - No
Operating System qualcomm sdm640_firmware - Yes
Hardware qualcomm sdm640 - No
Operating System qualcomm sdm658_firmware - Yes
Hardware qualcomm sdm658 - No
Operating System qualcomm sdm660_firmware - Yes
Hardware qualcomm sdm660 - No
Operating System qualcomm sdm670_firmware - Yes
Hardware qualcomm sdm670 - No
Operating System qualcomm sdm710_firmware - Yes
Hardware qualcomm sdm710 - No
Operating System qualcomm sdm712_firmware - Yes
Hardware qualcomm sdm712 - No
Operating System qualcomm sdm830_firmware - Yes
Hardware qualcomm sdm830 - No
Operating System qualcomm sdm845_firmware - Yes
Hardware qualcomm sdm845 - No
Operating System qualcomm sdm850_firmware - Yes
Hardware qualcomm sdm850 - No
Operating System qualcomm sdpx55m_firmware - Yes
Hardware qualcomm sdpx55m - No
Operating System qualcomm sdx24_firmware - Yes
Hardware qualcomm sdx24 - No
Operating System qualcomm sdx24m_firmware - Yes
Hardware qualcomm sdx24m - No
Operating System qualcomm sdx55_firmware - Yes
Hardware qualcomm sdx55 - No
Operating System qualcomm sm4250_firmware - Yes
Hardware qualcomm sm4250 - No
Operating System qualcomm sm6125_firmware - Yes
Hardware qualcomm sm6125 - No
Operating System qualcomm sm6150_firmware - Yes
Hardware qualcomm sm6150 - No
Operating System qualcomm sm6150p_firmware - Yes
Hardware qualcomm sm6150p - No
Operating System qualcomm sm6250_firmware - Yes
Hardware qualcomm sm6250 - No
Operating System qualcomm sm6250p_firmware - Yes
Hardware qualcomm sm6250p - No
Operating System qualcomm sm7125_firmware - Yes
Hardware qualcomm sm7125 - No
Operating System qualcomm sm7150_firmware - Yes
Hardware qualcomm sm7150 - No
Operating System qualcomm sm7150p_firmware - Yes
Hardware qualcomm sm7150p - No
Operating System qualcomm sm7250_firmware - Yes
Hardware qualcomm sm7250 - No
Operating System qualcomm sm7250p_firmware - Yes
Hardware qualcomm sm7250p - No
Operating System qualcomm sm8150_firmware - Yes
Hardware qualcomm sm8150 - No
Operating System qualcomm sm8150p_firmware - Yes
Hardware qualcomm sm8150p - No
Operating System qualcomm sm8250_firmware - Yes
Hardware qualcomm sm8250 - No
Operating System qualcomm sxr2130_firmware - Yes
Hardware qualcomm sxr2130 - No
Operating System qualcomm sxr2130p_firmware - Yes
Hardware qualcomm sxr2130p - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For qualcomm's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.