CVE-2021-30327

MEDIUMCVSS 6.8/10EPSS 0.17%

Last modified

CVE-2021-30327 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon Voice & Music. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon Voice & Music

Metrics

CVSS 3.1
6.8/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.17%

6.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
QualcommApq8097 FirmwareAll versions
QualcommApq8098 FirmwareAll versions
QualcommIpq6000 FirmwareAll versions
QualcommIpq6005 FirmwareAll versions
QualcommIpq6010 FirmwareAll versions
QualcommIpq6018 FirmwareAll versions
QualcommIpq6028 FirmwareAll versions
QualcommMdm9205 FirmwareAll versions
QualcommMsm8997 FirmwareAll versions
QualcommMsm8998 FirmwareAll versions
QualcommQca6595 FirmwareAll versions
QualcommQca6595au FirmwareAll versions
QualcommQcn7605 FirmwareAll versions
QualcommQcn7605w FirmwareAll versions
QualcommQcn7606 FirmwareAll versions
QualcommQcn7606w FirmwareAll versions
QualcommQcs401 FirmwareAll versions
QualcommQcs402 FirmwareAll versions
QualcommQcs403 FirmwareAll versions
QualcommQcs404 FirmwareAll versions
QualcommQcs405 FirmwareAll versions
QualcommQcs407 FirmwareAll versions
QualcommSa2145p FirmwareAll versions
QualcommSa2150p FirmwareAll versions
QualcommSa4150p FirmwareAll versions
QualcommSa4155p FirmwareAll versions
QualcommSa415m FirmwareAll versions
QualcommSa4250p FirmwareAll versions
QualcommSa515m FirmwareAll versions
QualcommSa6115 FirmwareAll versions
QualcommSa6115p FirmwareAll versions
QualcommSa6125 FirmwareAll versions
QualcommSa6125p FirmwareAll versions
QualcommSa6145 FirmwareAll versions
QualcommSa6145p FirmwareAll versions
QualcommSa615x FirmwareAll versions
QualcommSa615xp FirmwareAll versions
QualcommSa8150p FirmwareAll versions
QualcommSa8155 FirmwareAll versions
QualcommSa8155p FirmwareAll versions
QualcommSa8195p FirmwareAll versions
QualcommSc7180 FirmwareAll versions
QualcommSc7180p FirmwareAll versions
QualcommSc8180x FirmwareAll versions
QualcommSc8180xp FirmwareAll versions
QualcommSda658 FirmwareAll versions
QualcommSda660 FirmwareAll versions
QualcommSda670 FirmwareAll versions
QualcommSda830 FirmwareAll versions
QualcommSda845 FirmwareAll versions

Showing 50 of 79 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-30327?
Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon Voice & Music
How severe is CVE-2021-30327?
CVE-2021-30327 has a CVSS score of 6.8/10 (MEDIUM severity). The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2021-30327?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-30327?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST