← Back to search

CVE-2026-24084

7.5 HIGH

Published 2026-08-04 · Updated 2026-08-06

AI risk analysis

Summary
The flaw allows attackers to exploit weak UE configuration checks, potentially leading to unauthorized access or data compromise without proper verification of security capabilities.
Exploitability
Exploitation requires an attacker to manipulate UE additional security capabilities and may be moderately difficult due to the need for precise timing and capability manipulation.
Blast radius
If exploited, this could impact a wide range of devices using affected Qualcomm firmware, leading to significant data or system integrity issues.
Prioritized remediation
Update all affected Qualcomm firmware to the latest versions that address the configuration flaw.
firmwaresecurity-capabilitiesue

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-1294

Vendors

qualcomm

Products

sdx57m firmware, sdx57m, sdx61 firmware, sdx61, sdx71m firmware, sdx71m, sm6650p firmware, sm6650p, sm7325p firmware, sm7325p, sm7435 firmware, sm7435

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.