7.8

CVE-2025-21476

Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.

Data is provided by the National Vulnerability Database (NVD)
QualcommQcs6490 Firmware Version-
   QualcommQcs6490 Version-
QualcommQcs8550 Firmware Version-
   QualcommQcs8550 Version-
QualcommQcs9100 Firmware Version-
   QualcommQcs9100 Version-
QualcommSg8275 Firmware Version-
   QualcommSg8275 Version-
QualcommSg8275p Firmware Version-
   QualcommSg8275p Version-
QualcommSm6650 Firmware Version-
   QualcommSm6650 Version-
QualcommSm7635 Firmware Version-
   QualcommSm7635 Version-
QualcommSm7675 Firmware Version-
   QualcommSm7675 Version-
QualcommSm7675p Firmware Version-
   QualcommSm7675p Version-
QualcommSm8550 Firmware Version-
   QualcommSm8550 Version-
QualcommSm8550p Firmware Version-
   QualcommSm8550p Version-
QualcommSm8635 Firmware Version-
   QualcommSm8635 Version-
QualcommSm8635p Firmware Version-
   QualcommSm8635p Version-
QualcommSm8650 Firmware Version-
   QualcommSm8650 Version-
QualcommSm8650p Firmware Version-
   QualcommSm8650p Version-
QualcommSm8650q Firmware Version-
   QualcommSm8650q Version-
QualcommSm8750 Firmware Version-
   QualcommSm8750 Version-
QualcommSm8750p Firmware Version-
   QualcommSm8750p Version-
QualcommSxr2330p Firmware Version-
   QualcommSxr2330p Version-
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
QualcommQca6698aq Firmware Version-
   QualcommQca6698aq Version-
QualcommQcn9011 Firmware Version-
   QualcommQcn9011 Version-
QualcommQcn9012 Firmware Version-
   QualcommQcn9012 Version-
QualcommQcn9274 Firmware Version-
   QualcommQcn9274 Version-
QualcommWcn3910 Firmware Version-
   QualcommWcn3910 Version-
QualcommWcn3950 Firmware Version-
   QualcommWcn3950 Version-
QualcommWcn6650 Firmware Version-
   QualcommWcn6650 Version-
QualcommWcn6750 Firmware Version-
   QualcommWcn6750 Version-
QualcommWcn6755 Firmware Version-
   QualcommWcn6755 Version-
QualcommWcn6855 Firmware Version-
   QualcommWcn6855 Version-
QualcommWcn6856 Firmware Version-
   QualcommWcn6856 Version-
QualcommWcn7850 Firmware Version-
   QualcommWcn7850 Version-
QualcommWcn7851 Firmware Version-
   QualcommWcn7851 Version-
QualcommWcn7860 Firmware Version-
   QualcommWcn7860 Version-
QualcommWcn7861 Firmware Version-
   QualcommWcn7861 Version-
QualcommWcn7880 Firmware Version-
   QualcommWcn7880 Version-
QualcommWcn7881 Firmware Version-
   QualcommWcn7881 Version-
QualcommQcm5430 Firmware Version-
   QualcommQcm5430 Version-
QualcommQcm6490 Firmware Version-
   QualcommQcm6490 Version-
QualcommQcm8550 Firmware Version-
   QualcommQcm8550 Version-
QualcommQcs5430 Firmware Version-
   QualcommQcs5430 Version-
QualcommQcs615 Firmware Version-
   QualcommQcs615 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.01% 0.014
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
product-security@qualcomm.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.