CVE-2026-24078
Received Received - Intake

IPSec Negotiation Failure Leads to Information Disclosure in NG-eCall SIP

Vulnerability report for CVE-2026-24078, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: Qualcomm, Inc.

Description

Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qualcomm ng-ecall *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-359 The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves information disclosure when IPSec negotiation fails or is not properly established during NG-eCall SIP signaling. NG-eCall is a next-generation emergency call system used in vehicles.

Impact Analysis

If exploited, this vulnerability could allow unauthorized parties to access sensitive information during failed IPSec negotiations in NG-eCall SIP signaling, potentially exposing confidential data.

Compliance Impact

The vulnerability may lead to information disclosure during IPSec negotiation failures in NG-eCall SIP signaling, which could potentially expose sensitive data. This could impact compliance with GDPR (data protection) and HIPAA (health information privacy) by increasing the risk of unauthorized data exposure.

Mitigation Strategies

Ensure proper IPSec negotiation during NG-eCall SIP signaling to prevent information disclosure. Verify IPSec policies and configurations are correctly implemented and enforced.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24078. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart