CVE-2026-24084
Received
Received - Intake
UE Security Capability Replay Weak Configuration Vulnerability
Vulnerability report for CVE-2026-24084, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-04
Last updated on: 2026-08-04
Assigner: Qualcomm, Inc.
Description
Description
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1294 | The System-on-Chip (SoC) implements a Security Identifier mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Identifiers are not correctly implemented. |