Security readout for executives and security teams
Plain-English summary
CVE-2021-35078 is a Qualcomm Snapdragon vulnerability that can cause memory to leak when a device parses an overly long server certificate chain. The documented impact is availability, not data theft or tampering. Affected Snapdragon components span mobile, automotive, compute, IoT, connectivity, and wearable product lines.
Executive priority
Treat this as a high-priority availability risk for affected Snapdragon-based fleets, especially operational, IoT, automotive, and mobile environments. The main decision is patch availability through OEMs and carriers, not custom application remediation.
Technical view
The issue is improper validation of server certificate chain length during certificate parsing, leading to a possible memory leak. CVSS 3.1 is 7.5: network exploitable, low complexity, no privileges, no user interaction, unchanged scope, and high availability impact only.
Likely exposure
Exposure is most likely in products using the listed Qualcomm Snapdragon chipsets or connectivity/audio components. Business impact depends on whether OEM firmware includes Qualcomm's May 2022 security fixes and whether deployed devices parse untrusted server certificate chains.
Exploitation context
The provided sources do not report active exploitation, and this CVE is not marked as CISA KEV. The CVSS vector indicates remote network reachability without authentication or user interaction, but the bundle does not provide exploit details or real-world incident evidence.
Researcher notes
Evidence is limited to CVE data and Qualcomm's bulletin reference. No CWE is supplied. The affected list is broad and component-specific, so validation should focus on chipset and firmware lineage rather than product names alone.
Mitigation direction
- Identify products using affected Qualcomm Snapdragon components.
- Check Qualcomm May 2022 bulletin and OEM advisories for applicable fixes.
- Apply OEM firmware, driver, or platform updates that include Qualcomm's fix.
- Prioritize internet-connected, unmanaged, or safety-critical device fleets.
- Monitor affected devices for memory exhaustion, crashes, or service degradation.
Validation and detection
- Map device models to Qualcomm chipset identifiers in the affected list.
- Verify installed firmware or patch level against OEM security advisories.
- Confirm vendor documentation references CVE-2021-35078 or Qualcomm May 2022 fixes.
- Review crash, reboot, and memory telemetry for unexplained availability issues.
- Track exceptions where OEM firmware is unavailable or unsupported.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-35078 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.5HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://www.qualcomm.com/company/product-security/bulletins/may-2022-bulletinCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
