Impact
This vulnerability results from a weak configuration in Qualcomm Software Center that allows temporary files to be created with insecure permissions. The flaw is a classic case of improper handling of temporary files, potentially leading to privileged code execution if an attacker can set the ownership or permissions of the file in a way that enables elevation. The associated weakness is identified as CWE-378 – Creation of Temporary File with Insecure Permissions. The impact is the ability to gain higher privileges on a device running affected Snapdragon software, thereby compromising confidentiality, integrity, and availability for the affected system.
Affected Systems
The affected systems are Qualcomm Snapdragon devices as listed under the Qualcomm, Inc. Snapdragon product line. No specific version information is provided, so all Snapdragon firmware or Software Center releases that contain the insecure temporary file handling configuration are at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. The EPSS score is not available, so the current risk of exploitation cannot be quantified precisely, but the high CVSS suggests significant potential for exploitation. This issue is not listed in CISA KEV, indicating no documented public exploit at the time of analysis. The likely attack vector is inferred to be one where an attacker can influence temporary file creation, possibly via a local or remote user action that can set file permissions or attributes. No specific prerequisites are stated, but the vulnerability depends on the configuration of temporary file handling in the software center.
OpenCVE Enrichment