PT-2022-10428 · Qualcomm · Snapdragon Mobile+1

Published

2022-06-14

·

Updated

2023-04-19

·

CVE-2021-35111

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Snapdragon Connectivity, Snapdragon Mobile (affected versions not specified)
Description The issue is related to improper validation of tag id while RRC sends tag id to MAC, leading to a Time-of-Check-to-Time-of-Use (TOCTOU) race condition. This affects Snapdragon Connectivity and Snapdragon Mobile.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-35111

Affected Products

Snapdragon Connectivity
Snapdragon Mobile