Cyber Posture

CVE-2024-53011

High

Published: 03 March 2025

Published
03 March 2025
Modified
11 August 2025
KEV Added
Patch
CVSS Score 7.9 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS Score 0.0007 20.7th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Information disclosure may occur due to improper permission and access controls to Video Analytics engine.

Security Summary

CVE-2024-53011 is an information disclosure vulnerability stemming from improper permission and access controls in the Video Analytics engine. It affects Qualcomm components, as detailed in the vendor's security bulletin. The issue is rated with a CVSS v3.1 base score of 7.9 (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N) and is associated with CWE-264 (Permissions, Privileges, and Access Controls) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerability was published on March 3, 2025.

Exploitation requires local access (AV:L) with low attack complexity (AC:L) and high privileges (PR:H), needing no user interaction (UI:N). Successful attacks have a changed scope (S:C), enabling high confidentiality (C:H) and integrity (I:H) impacts with no availability disruption (A:N). A privileged local attacker could leverage the flawed controls to disclose sensitive information from the Video Analytics engine and potentially modify data.

For mitigation details, refer to the Qualcomm March 2025 Security Bulletin at https://docs.qualcomm.com/product/publicresources/securitybulletin/march-2025-bulletin.html, which provides guidance on patches and workarounds.

Details

CWE(s)
CWE-264CWE-200

Affected Products

qualcomm
snapdragon 8\+ gen 1 mobile platform firmware
all versions
qualcomm
snapdragon 8\+ gen 2 mobile platform firmware
all versions
qualcomm
snapdragon ar1 gen 1 platform \"luna1\" firmware
all versions
qualcomm
fastconnect 6700 firmware
all versions
qualcomm
fastconnect 6900 firmware
all versions
qualcomm
fastconnect 7800 firmware
all versions
qualcomm
flight rb5 5g platform firmware
all versions
qualcomm
qca6391 firmware
all versions
qualcomm
qca6564 firmware
all versions
qualcomm
qca6564au firmware
all versions
+73 more product configuration(s) — see NVD for full list

References