CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:C/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
12.6%
RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Vendor | Product | Version | CPE |
---|---|---|---|
qualcomm | ar8035_firmware | - | cpe:2.3:o:qualcomm:ar8035_firmware:-:*:*:*:*:*:*:* |
qualcomm | ar8035 | - | cpe:2.3:h:qualcomm:ar8035:-:*:*:*:*:*:*:* |
qualcomm | qca9984_firmware | - | cpe:2.3:o:qualcomm:qca9984_firmware:-:*:*:*:*:*:*:* |
qualcomm | qca9984 | - | cpe:2.3:h:qualcomm:qca9984:-:*:*:*:*:*:*:* |
qualcomm | qcm2290_firmware | - | cpe:2.3:o:qualcomm:qcm2290_firmware:-:*:*:*:*:*:*:* |
qualcomm | qcm2290 | - | cpe:2.3:h:qualcomm:qcm2290:-:*:*:*:*:*:*:* |
qualcomm | qcm4290_firmware | - | cpe:2.3:o:qualcomm:qcm4290_firmware:-:*:*:*:*:*:*:* |
qualcomm | qcm4290 | - | cpe:2.3:h:qualcomm:qcm4290:-:*:*:*:*:*:*:* |
qualcomm | qcs2290_firmware | - | cpe:2.3:o:qualcomm:qcs2290_firmware:-:*:*:*:*:*:*:* |
qualcomm | qcs2290 | - | cpe:2.3:h:qualcomm:qcs2290:-:*:*:*:*:*:*:* |
[
{
"product": "Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking",
"vendor": "Qualcomm, Inc.",
"versions": [
{
"status": "affected",
"version": "AR8035, QCA9984, QCM2290, QCM4290, QCS2290, QCS405, QCS4290, SD460, SD480, SD662, SD680, SM6375, SW5100, SW5100P, WCD9370, WCD9375, WCD9385, WCN3910, WCN3950, WCN3980, WCN3988, WCN3991, WCN3998, WCN3999, WSA8810, WSA8815, WSA8830, WSA8835"
}
]
}
]
More
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:C/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
12.6%