PT-2021-6922 · Qualcomm · Qualcomm Snapdragon Industrial Iot+5

Published

2021-11-01

·

Updated

2021-11-16

·

CVE-2021-1982

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile (affected versions not specified)
Description The issue is related to improper input validation of received NAS OTA messages, which could lead to a denial of service scenario. It is also mentioned that the vulnerability is associated with the use of the assert() function or similar operators in Qualcomm's embedded software. This could allow a remote attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02680
CVE-2021-1982

Affected Products

Qualcomm Snapdragon Auto
Qualcomm Snapdragon Compute
Qualcomm Snapdragon Connectivity
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Industrial Iot
Qualcomm Snapdragon Mobile