Impact
The vulnerability is a stack-based buffer overflow caused by copying unverified external data without checking the buffer size. The flaw allows an attacker to overwrite adjacent memory, leading to potential code execution, crashing the component, or escalating privileges. This exception falls under CWE-121 and can compromise confidentiality, integrity, or availability if exploited.
Affected Systems
Qualcomm Inc. Snapdragon devices are affected. No specific firmware or product versions were listed in the advisory; therefore, all Snapdragon builds that include the OOBM component should be treated as at risk until a patch is applied or the vendor discloses affected versions.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % suggests a low current exploitation probability. OOBM receives no entry in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of malformed external input—potentially over the network or a user-supplied interface—to trigger the overflow. Successful exploitation would require the attacker to provide data that exceeds the buffer size; this could be achieved remotely if the component accepts external input over an exposed channel, or locally if an attacker can craft a payload that feeds the OOBM routine.
OpenCVE Enrichment