CVE-2021-1905
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Qualcomm Multiple Chipsets Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-416
מוצרים מושפעים
qualcomm: apq8009 firmware; qualcomm: apq8009; qualcomm: apq8009w firmware; qualcomm: apq8009w; qualcomm: apq8017 firmware; qualcomm: apq8017; qualcomm: apq8053 firmware; qualcomm: apq8053; qualcomm: apq8064au firmware; qualcomm: apq8064au; qualcomm: apq8096au firmware; qualcomm: apq8096au; qualcomm: aqt1000 firmware; qualcomm: aqt1000; qualcomm: ar8031 firmware
קישורים
- https://www.qualcomm.com/company/product-security/bulletins/may-2021-bulletin PatchVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/may-2021-bulletin PatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource