Description
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Published: 2026-08-04
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from a weak configuration in which the user equipment does not verify that its additional security capabilities match the replayed capabilities it receives. This inconsistency may enable an attacker to manipulate the communication session and embed malicious capabilities or instructions that the target device fails to reject. The CWE associated with this flaw is CWE‑1294, which focuses on improper verification of fallback or supplemental credentials, indicating that the device can be tricked into accepting authentication or configuration data that it should reject.

Affected Systems

The affected systems are Qualcomm Snapdragon mobile platforms. No specific version information was provided, so all current Snapdragon implementations that rely on the multi‑mode call processor and have the described configuration flaw are potentially impacted.

Risk and Exploitability

With a CVSS score of 7.5, the defect poses a medium‑high risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely reported as a priority or actively exploited. However, the lack of verification gives attackers a feasible path to influence security capabilities, especially if the device is exposed to external communication traffic. The impact could range from unauthorized access to denial of service if the malicious capabilities disrupt normal operation. Administrators should consider that the flaw could be exploited from the network side when the UE processes replayed capability messages.

Generated by OpenCVE AI on August 4, 2026 at 19:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure the device to enforce consistency checks between added and replayed security capabilities
  • Apply any Qualcomm Snapdragon firmware updates that address the security identifier mechanism flaw
  • Implement network filtering or monitoring to detect suspicious replayed capability exchanges
  • If a patch is unavailable, restrict the use of the affected multi‑mode call processor until a fix is released

Generated by OpenCVE AI on August 4, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Qualcomm
Qualcomm snapdragon
Vendors & Products Qualcomm
Qualcomm snapdragon

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Title Insecure Security Identifier Mechanism in Multi-Mode Call Processor
Weaknesses CWE-1294
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Qualcomm Snapdragon
cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2026-08-04T15:52:44.474Z

Reserved: 2026-01-21T12:51:13.996Z

Link: CVE-2026-24084

cve-icon Vulnrichment

Updated: 2026-08-04T15:52:39.630Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:45:03Z

Weaknesses
  • CWE-1294

    Insecure Security Identifier Mechanism