Security readout for executives and security teams
Plain-English summary
This Qualcomm vulnerability could let a local, low-privileged actor read sensitive secure resources on affected Snapdragon Industrial IoT and Mobile platforms. The known impact is information disclosure, not system takeover or service disruption. Public sources provided do not show active exploitation.
Executive priority
Treat this as a moderate confidentiality risk. It deserves planned remediation through normal firmware and OEM update channels, with higher priority for sensitive mobile or IoT deployments. There is no provided evidence of active exploitation.
Technical view
CVE-2021-35070 is caused by improper SMMU configuration, allowing the RPM secure Stream to access secure resources it should not. CVSS 3.1 is 6.5, with local access, low complexity, low privileges, no user interaction, changed scope, high confidentiality impact, and no integrity or availability impact.
Likely exposure
Exposure is most likely in devices or products built on the listed Qualcomm Snapdragon Industrial IoT or Mobile components: QCM6125, QCS6125, SD665, WCD9370, WCD9375, WCN3950, WCN3980, WSA8810, and WSA8815.
Exploitation context
The provided sources do not identify active exploitation, and this CVE is not marked KEV. The CVSS vector indicates exploitation requires local access and low privileges, with no user interaction. Public evidence in the bundle does not include exploit details.
Researcher notes
The bundle names improper SMMU configuration and RPM secure Stream overreach as the root issue. No CWE, exploit proof, detailed patch metadata, or product model mapping is provided. Avoid assuming exposure beyond the listed Qualcomm platforms and components.
Mitigation direction
- Check Qualcomm’s April 2022 security bulletin and relevant OEM firmware guidance.
- Identify products using the listed Qualcomm chipsets or components.
- Apply OEM-provided firmware or platform updates that address CVE-2021-35070.
- Restrict local user and app privileges on affected devices until updates are confirmed.
- For managed fleets, prioritize devices handling sensitive data or deployed in exposed environments.
Validation and detection
- Inventory device models and hardware identifiers for listed Qualcomm components.
- Compare firmware builds against OEM advisories referencing Qualcomm’s April 2022 bulletin.
- Confirm whether CVE-2021-35070 is listed as fixed by the device vendor.
- Review mobile and IoT asset management data for unpatched affected platforms.
- Document unsupported devices where vendor fixes are unavailable or unclear.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-35070 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N24Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.5MediumVector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://www.qualcomm.com/company/product-security/bulletins/april-2022-bulletinCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
