CVE-2026-24084
7.5 HIGHPublished 2026-08-04 · Updated 2026-08-06
AI risk analysis
- Summary
- The flaw allows attackers to exploit weak UE configuration checks, potentially leading to unauthorized access or data compromise without proper verification of security capabilities.
- Exploitability
- Exploitation requires an attacker to manipulate UE additional security capabilities and may be moderately difficult due to the need for precise timing and capability manipulation.
- Blast radius
- If exploited, this could impact a wide range of devices using affected Qualcomm firmware, leading to significant data or system integrity issues.
- Prioritized remediation
- Update all affected Qualcomm firmware to the latest versions that address the configuration flaw.
firmwaresecurity-capabilitiesue
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-1294
Vendors
qualcomm
Products
sdx57m firmware, sdx57m, sdx61 firmware, sdx61, sdx71m firmware, sdx71m, sm6650p firmware, sm6650p, sm7325p firmware, sm7325p, sm7435 firmware, sm7435
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.