CVE-2026-24084: CWE-1294: Insecure Security Identifier Mechanism in Qualcomm, Inc. Snapdragon
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-24084) affects multiple Qualcomm Snapdragon chipsets and related products. It is characterized by a weakness in the security identifier mechanism, specifically due to the UE failing to verify the consistency of its additional security capabilities when these capabilities are replayed. The CVSS 3.1 base score is 7.5, indicating high severity, with an attack vector of network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), unchanged scope (S:U), high confidentiality impact (C:H), and no impact on integrity or availability (I:N, A:N). No known exploits are reported in the wild, and no official remediation or patch has been disclosed as of the published date.
Potential Impact
An attacker could exploit this vulnerability remotely without authentication or user interaction to compromise the confidentiality of data processed by affected Qualcomm Snapdragon devices. There is no impact on integrity or availability. The flaw stems from the UE's failure to verify the consistency of additional security capabilities when replayed, potentially allowing unauthorized access to sensitive information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or remediation level is provided, users and administrators should monitor Qualcomm's advisories for updates. Until a patch is available, consider applying any recommended temporary mitigations from Qualcomm if published. No specific mitigations are indicated in the current data.
CVE-2026-24084: CWE-1294: Insecure Security Identifier Mechanism in Qualcomm, Inc. Snapdragon
Description
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVSS v3.1
Score 7.5high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-24084) affects multiple Qualcomm Snapdragon chipsets and related products. It is characterized by a weakness in the security identifier mechanism, specifically due to the UE failing to verify the consistency of its additional security capabilities when these capabilities are replayed. The CVSS 3.1 base score is 7.5, indicating high severity, with an attack vector of network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), unchanged scope (S:U), high confidentiality impact (C:H), and no impact on integrity or availability (I:N, A:N). No known exploits are reported in the wild, and no official remediation or patch has been disclosed as of the published date.
Potential Impact
An attacker could exploit this vulnerability remotely without authentication or user interaction to compromise the confidentiality of data processed by affected Qualcomm Snapdragon devices. There is no impact on integrity or availability. The flaw stems from the UE's failure to verify the consistency of additional security capabilities when replayed, potentially allowing unauthorized access to sensitive information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or remediation level is provided, users and administrators should monitor Qualcomm's advisories for updates. Until a patch is available, consider applying any recommended temporary mitigations from Qualcomm if published. No specific mitigations are indicated in the current data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- qualcomm
- Date Reserved
- 2026-01-21T12:51:13.996Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a72084abf8831d5390c1533
Added to database: 08/04/2026, 15:42:02 UTC
Last enriched: 08/04/2026, 15:59:05 UTC
Last updated: 08/04/2026, 16:28:46 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.