2021-1890 | Qualcomm Snapdragon Auto RSA Import Key memory corruption


CVSS Meta Temp Score Current Exploit Price (≈) CTI Interest Score
7.5 $0-$5k 0.70

A vulnerability classified as critical has been found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music and Snapdragon Wearables (Chip Software). Affected is some unknown processing of the component RSA Import Key Handler. The manipulation with an unknown input leads to a memory corruption vulnerability. CWE is classifying the issue as CWE-119. This is going to have an impact on confidentiality, integrity, and availability. CVE summarizes:

Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

The weakness was published 07/13/2021. The advisory is shared for download at qualcomm.com. This vulnerability is traded as CVE-2021-1890 since 12/08/2020. The exploitability is told to be easy. The attack needs to be approached locally. Required for exploitation is a authentication. There are neither technical details nor an exploit publicly available. The current price for an exploit might be approx. USD $0-$5k (estimation calculated on 07/16/2021).

Upgrading eliminates this vulnerability.

Type

Vendor

Name

VulDB Meta Base Score: 7.8
VulDB Meta Temp Score: 7.5

VulDB Base Score: 7.8
VulDB Temp Score: 7.5
VulDB Vector: 🔒
VulDB Reliability: 🔍

AV AC Au C I A
🔍 🔍 🔍 🔍 🔍 🔍
🔍 🔍 🔍 🔍 🔍 🔍
🔍 🔍 🔍 🔍 🔍 🔍
Vector Complexity Authentication Confidentiality Integrity Availability
unlock unlock unlock unlock unlock unlock
unlock unlock unlock unlock unlock unlock
unlock unlock unlock unlock unlock unlock


VulDB Base Score: 🔒
VulDB Temp Score: 🔒
VulDB Reliability: 🔍
Class: Memory corruption
CWE: CWE-119
ATT&CK: Unknown

Local: Yes
Remote: No

Availability: 🔒
Status: Not defined

Price Prediction: 🔍
Current Price Estimation: 🔒


0-Day unlock unlock unlock unlock
Today unlock unlock unlock unlock

Threat Intelligenceinfoedit

Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍Recommended: Upgrade
Status: 🔍

0-Day Time: 🔒

Upgrade: qualcomm.com

12/08/2020 CVE assigned
07/13/2021 +216 days Advisory disclosed
07/13/2021 +0 days VulDB entry created
07/16/2021 +3 days VulDB last updateVendor: https://www.qualcomm.com/

Advisory: qualcomm.com
Status: Confirmed
Confirmation: 🔒

CVE: CVE-2021-1890 (🔒)

Created: 07/13/2021 16:41
Updated: 07/16/2021 06:07
Changes: (1) source_cve_cna
Complete: 🔍

Download it now for free!



Source link