Impact
Improper authorization on the Qualcomm Snapdragon Software Center’s SocketIO interface allows an attacker to execute arbitrary code with system privileges, completely compromising confidentiality, integrity, and availability. The flaw is a classic example of the weakness identified by CWE-285, Unauthorized access via improper authorization.
Affected Systems
The vulnerability affects Qualcomm, Inc.’s Snapdragon software. The data do not specify exact affected versions, so any installation of Snapdragon that includes the exposed SocketIO endpoint could be vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the absence of an EPSS score does not diminish the risk. The flaw is publicly documented but not listed in the CISA KEV catalog. It can be exploited over a network by an attacker with access to the SocketIO interface, providing an attitude for remote code execution without needing elevated privileges on the target system.
OpenCVE Enrichment