Qualcomm BT Controller Transient Denial-of-Service Vulnerability via UCI Command Processing

Vulnerability

A transient denial-of-service vulnerability has been identified in the Bluetooth (BT) controller of various chipsets. This issue arises from improper handling of UCI commands, which can lead to temporary disruptions in service.

Impact

Exploitation of this vulnerability can cause a transient denial-of-service condition, disrupting normal operations by temporarily causing a service or function to become unavailable or unresponsive.

Remediation

Qualcomm has notified customers about this vulnerability and provided patch instructions. The patch can be applied by following the instructions available in the Qualcomm March 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.