CVE-2025-21449
BaseFortify
Publication date: 2025-07-08
Last updated on: 2026-02-10
Assigner: Qualcomm, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qualcomm | smart_audio_200_platform_firmware | * |
| qualcomm | smart_audio_400_platform_firmware | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
| CWE-126 | The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a transient denial of service (DOS) that can occur when processing a malformed length field in SSID Information Elements (IEs). Essentially, if an attacker sends malformed data in the SSID field, it can cause temporary disruption of service.
How can this vulnerability impact me? :
The impact of this vulnerability is a transient denial of service, meaning that affected systems may temporarily become unavailable or unresponsive when processing malformed SSID data. This could disrupt network connectivity or services relying on wireless communication.