Qualcomm Multi-Mode Call Processor Improper Validation of Array Index Vulnerability Allowing Memory Corruption

Vulnerability

A critical vulnerability has been identified in the Qualcomm Multi-Mode Call Processor, specifically in the handling of the PLMN selection from the SOR failed list. This issue arises from improper validation of array indices, leading to memory corruption. The vulnerability is accessible remotely and affects several chipsets within the Qualcomm 5G IoT Modem, as well as various Snapdragon and QCA chipsets.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to arbitrary code execution or application crashes.

Remediation

Qualcomm has notified device manufacturers about this vulnerability and is actively sharing patches. For information on the patching status of released devices, contact the device manufacturer.

Added: Sep 24, 2025, 5:09 PM
Updated: Sep 24, 2025, 5:09 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.