8.6

CVE-2025-21480

Warnung
Medienbericht

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommAqt1000 Firmware Version-
   QualcommAqt1000 Version-
QualcommQca6391 Firmware Version-
   QualcommQca6391 Version-
QualcommQcm4490 Firmware Version-
   QualcommQcm4490 Version-
QualcommQcs4490 Firmware Version-
   QualcommQcs4490 Version-
QualcommSc8380xp Firmware Version-
   QualcommSc8380xp Version-
QualcommSd855 Firmware Version-
   QualcommSd855 Version-
QualcommSm4635 Firmware Version-
   QualcommSm4635 Version-
QualcommSm6250 Firmware Version-
   QualcommSm6250 Version-
QualcommSm6650 Firmware Version-
   QualcommSm6650 Version-
QualcommSm6650p Firmware Version-
   QualcommSm6650p Version-
QualcommSm7325p Firmware Version-
   QualcommSm7325p Version-
QualcommSm7635 Firmware Version-
   QualcommSm7635 Version-
QualcommSm7675 Firmware Version-
   QualcommSm7675 Version-
QualcommSm7675p Firmware Version-
   QualcommSm7675p Version-
QualcommSm8550p Firmware Version-
   QualcommSm8550p Version-
QualcommSm8635 Firmware Version-
   QualcommSm8635 Version-
QualcommSm8635p Firmware Version-
   QualcommSm8635p Version-
QualcommSm8650q Firmware Version-
   QualcommSm8650q Version-
QualcommSxr2230p Firmware Version-
   QualcommSxr2230p Version-
QualcommSxr2250p Firmware Version-
   QualcommSxr2250p Version-
QualcommSxr2330p Firmware Version-
   QualcommSxr2330p Version-
QualcommWcd9341 Firmware Version-
   QualcommWcd9341 Version-
QualcommWcd9370 Firmware Version-
   QualcommWcd9370 Version-
QualcommWcd9375 Firmware Version-
   QualcommWcd9375 Version-
QualcommWcd9378 Firmware Version-
   QualcommWcd9378 Version-
QualcommWcd9380 Firmware Version-
   QualcommWcd9380 Version-
QualcommWcd9385 Firmware Version-
   QualcommWcd9385 Version-
QualcommWcd9390 Firmware Version-
   QualcommWcd9390 Version-
QualcommWcd9395 Firmware Version-
   QualcommWcd9395 Version-
QualcommWcn3950 Firmware Version-
   QualcommWcn3950 Version-
QualcommWcn3988 Firmware Version-
   QualcommWcn3988 Version-
QualcommWcn6450 Firmware Version-
   QualcommWcn6450 Version-
QualcommWcn6650 Firmware Version-
   QualcommWcn6650 Version-
QualcommWcn6755 Firmware Version-
   QualcommWcn6755 Version-
QualcommWcn7861 Firmware Version-
   QualcommWcn7861 Version-
QualcommWcn7881 Firmware Version-
   QualcommWcn7881 Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
QualcommWsa8830 Firmware Version-
   QualcommWsa8830 Version-
QualcommWsa8832 Firmware Version-
   QualcommWsa8832 Version-
QualcommWsa8835 Firmware Version-
   QualcommWsa8835 Version-
QualcommWsa8840 Firmware Version-
   QualcommWsa8840 Version-
QualcommWsa8845 Firmware Version-
   QualcommWsa8845 Version-
QualcommWsa8845h Firmware Version-
   QualcommWsa8845h Version-

03.06.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Schwachstelle

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.98% 0.83
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
product-security@qualcomm.com 8.6 1.8 6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.