Impact
The vulnerability is an out-of-bounds write in diagnostic services caused by missing input validation. This flaw can corrupt memory, potentially allowing an attacker to tamper with device state, compromise integrity, or enable further exploitation leading to privilege escalation or denial of service. The primary weakness identified is CWE-787.
Affected Systems
Qualcomm, Inc. Snapdragon devices are affected. No specific firmware or model versions are listed, so the impact may span across all Snapdragon platforms that include the vulnerable diagnostic services.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, suggesting no widely reported active exploitation yet. Likely attack vectors involve access to the diagnostic services, which may require privileged or local execution on the device. The risk is moderate but should be monitored in environments where diagnostic services are exposed.
OpenCVE Enrichment