Impact
The vulnerability arises when IPSec negotiation fails or is not established correctly during NG‑eCall SIP signaling. Because of this failure, private personal information that is normally protected by the IPSec tunnel can be exposed to an unauthorized actor. The weakness is recognized as CWE‑359, which is an authentication or privacy failure that results in the disclosure of sensitive data. The consequence is the unauthorized disclosure of potentially confidential personal data used in emergency call scenarios, and could compromise confidentiality without affecting integrity or availability.
Affected Systems
Qualcomm Snapdragon devices are affected. The description does not specify exact firmware or hardware revisions, so any Snapdragon variant that implements NG‑eCall SIP signaling and relies on IPSec for secure transport is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been reported. The likely attack vector is inferred to be access to the NG‑eCall SIP signaling environment, which could be local on the device or remote through the network if the attacker can influence or observe the negotiation. Given the need for a specific protocol failure, the probability of exploitation is uncertain but not negligible.
OpenCVE Enrichment