LiveActive security incident?Get immediate response
CVE Record

CVE-2021-35070: RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to informa...

RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile

MediumCVSS 6.5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This Qualcomm vulnerability could let a local, low-privileged actor read sensitive secure resources on affected Snapdragon Industrial IoT and Mobile platforms. The known impact is information disclosure, not system takeover or service disruption. Public sources provided do not show active exploitation.

Executive priority

Treat this as a moderate confidentiality risk. It deserves planned remediation through normal firmware and OEM update channels, with higher priority for sensitive mobile or IoT deployments. There is no provided evidence of active exploitation.

Technical view

CVE-2021-35070 is caused by improper SMMU configuration, allowing the RPM secure Stream to access secure resources it should not. CVSS 3.1 is 6.5, with local access, low complexity, low privileges, no user interaction, changed scope, high confidentiality impact, and no integrity or availability impact.

Likely exposure

Exposure is most likely in devices or products built on the listed Qualcomm Snapdragon Industrial IoT or Mobile components: QCM6125, QCS6125, SD665, WCD9370, WCD9375, WCN3950, WCN3980, WSA8810, and WSA8815.

Exploitation context

The provided sources do not identify active exploitation, and this CVE is not marked KEV. The CVSS vector indicates exploitation requires local access and low privileges, with no user interaction. Public evidence in the bundle does not include exploit details.

Researcher notes

The bundle names improper SMMU configuration and RPM secure Stream overreach as the root issue. No CWE, exploit proof, detailed patch metadata, or product model mapping is provided. Avoid assuming exposure beyond the listed Qualcomm platforms and components.

Mitigation direction

  • Check Qualcomm’s April 2022 security bulletin and relevant OEM firmware guidance.
  • Identify products using the listed Qualcomm chipsets or components.
  • Apply OEM-provided firmware or platform updates that address CVE-2021-35070.
  • Restrict local user and app privileges on affected devices until updates are confirmed.
  • For managed fleets, prioritize devices handling sensitive data or deployed in exposed environments.

Validation and detection

  • Inventory device models and hardware identifiers for listed Qualcomm components.
  • Compare firmware builds against OEM advisories referencing Qualcomm’s April 2022 bulletin.
  • Confirm whether CVE-2021-35070 is listed as fixed by the device vendor.
  • Review mobile and IoT asset management data for unpatched affected platforms.
  • Document unsupported devices where vendor fixes are unavailable or unclear.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-35070 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.5CVSS 3.1MediumCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N24Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

6.5Medium
CVSS 3.1 vector shape for CVE-2021-35070Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Qualcomm, Inc.Snapdragon Industrial IOT, Snapdragon MobileQCM6125, QCS6125, SD665, WCD9370, WCD9375, WCN3950, WCN3980, WSA8810, WSA8815Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.