Impact
The flaw is a cryptographic issue that occurs when the modem processes registration requests that either lack proper authentication parameters or contain malformed data. This defect allows an attacker to craft or omit authentication tokens, potentially bypassing the modem’s verification step and gaining unauthorized access to the data modem’s functionality. The impact is the loss of confidentiality and integrity of the registration process, which may enable unauthorized configuration changes or data leakage. The weakness is categorized as CWE‑306.
Affected Systems
The vulnerability affects firmware running on Qualcomm Snapdragon data modem devices. No specific firmware or release versions are listed in the advisory, so all Snapdragon modems with the affected registration handling code are potentially impacted.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. No EPSS score is available, so the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting that it may not yet have active exploits. The likely attack vector is via network traffic that targets the modem’s registration request interface, and the attacker would need the ability to inject custom registration messages. If successful, the attacker could bypass authentication and act as a legitimate user.
OpenCVE Enrichment