CVE-2021-30304
CRITICALCVSS 9.1/10EPSS 0.59%
Last modified
CVE-2021-30304 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Qca2062 Firmware | All versions |
| Qualcomm | Qca2064 Firmware | All versions |
| Qualcomm | Qca2065 Firmware | All versions |
| Qualcomm | Qca2066 Firmware | All versions |
| Qualcomm | Sc8280xp Firmware | All versions |
| Qualcomm | Wcd9380 Firmware | All versions |
| Qualcomm | Wcd9385 Firmware | All versions |
| Qualcomm | Wcn6850 Firmware | All versions |
| Qualcomm | Wcn6851 Firmware | All versions |
| Qualcomm | Wcn6855 Firmware | All versions |
| Qualcomm | Wcn6856 Firmware | All versions |
| Qualcomm | Wsa8830 Firmware | All versions |
| Qualcomm | Wsa8835 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-30304?
Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity
How severe is CVE-2021-30304?
CVE-2021-30304 has a CVSS score of 9.1/10 (CRITICAL severity). The EPSS model estimates a 0.59% probability of exploitation in the next 30 days.
How do I fix CVE-2021-30304?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-30299Possible out of bound access in audio module due to lack of …6.7
- CVE-2021-3030Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross…6.1
- CVE-2021-30300Possible denial of service due to incorrectly decoding hex d…7.5
- CVE-2021-30301Possible denial of service due to out of memory while proces…7.5
- CVE-2021-30302Improper authentication of EAP WAPI EAPOL frames from unauth…7.5
- CVE-2021-30303Possible buffer overflow due to lack of buffer length check …7.8
- CVE-2021-30305Possible out of bound access due to lack of validation of pa…7.8
- CVE-2021-30306Possible buffer over read due to improper buffer allocation …7.1
- CVE-2021-30307Possible denial of service due to improper validation of DNS…7.5
- CVE-2021-30308Possible buffer overflow while printing the HARQ memory part…7.8
- CVE-2021-30309Improper size validation of QXDM commands can lead to memory…7.8
- CVE-2021-3031Padding bytes in Ethernet packets on PA-200, PA-220, PA-500,…4.3
Are you affected by CVE-2021-30304?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
