Qualcomm Products Asymmetric Key Generation Vulnerability for RKP Use Cases

Vulnerability

A vulnerability exists in various chipsets of Qualcomm products due to cryptographic issues in generating asymmetric key pairs for RKP (Robust Key Provisioning) use cases. This vulnerability could potentially be exploited to compromise the integrity of the key generation process, leading to unauthorized access or manipulation of cryptographic operations.

Impact

Exploitation of this vulnerability could result in improper key management, allowing for potential cryptographic attacks or unauthorized access to secured resources.

Remediation

Qualcomm has notified device manufacturers about this vulnerability and provided patch instructions. For information on the patching status of released devices, contact the device manufacturer.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
0.0
exploitability
3.5
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.