Impact
The vulnerability arises from a weak configuration in which the user equipment does not verify that its additional security capabilities match the replayed capabilities it receives. This inconsistency may enable an attacker to manipulate the communication session and embed malicious capabilities or instructions that the target device fails to reject. The CWE associated with this flaw is CWE‑1294, which focuses on improper verification of fallback or supplemental credentials, indicating that the device can be tricked into accepting authentication or configuration data that it should reject.
Affected Systems
The affected systems are Qualcomm Snapdragon mobile platforms. No specific version information was provided, so all current Snapdragon implementations that rely on the multi‑mode call processor and have the described configuration flaw are potentially impacted.
Risk and Exploitability
With a CVSS score of 7.5, the defect poses a medium‑high risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely reported as a priority or actively exploited. However, the lack of verification gives attackers a feasible path to influence security capabilities, especially if the device is exposed to external communication traffic. The impact could range from unauthorized access to denial of service if the malicious capabilities disrupt normal operation. Administrators should consider that the flaw could be exploited from the network side when the UE processes replayed capability messages.
OpenCVE Enrichment