CVE-2021-30260

HIGH

Qualcomm APQ8009 and other Snapdragon Firmware - Integer Overflow to Buffer Overflow via Extscan Hostlist Configuration

Title source: llm
STIX 2.1

Description

Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

References (1)

Core 1
Core References

Scores

CVSS v3 8.4
EPSS 0.0005
EPSS Percentile 16.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190 CWE-20
Status published
Products (50)
qualcomm/apq8009_firmware
qualcomm/apq8017_firmware
qualcomm/apq8053_firmware
qualcomm/apq8064au_firmware
qualcomm/apq8076_firmware
qualcomm/apq8092_firmware
qualcomm/apq8094_firmware
qualcomm/apq8096au_firmware
qualcomm/aqt1000_firmware
qualcomm/ar8031_firmware
... and 40 more
Published Sep 17, 2021
Tracked Since Feb 18, 2026