{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-27040","assignerOrgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","state":"PUBLISHED","assignerShortName":"qualcomm","dateReserved":"2025-02-18T09:19:46.883Z","datePublished":"2025-10-09T03:17:54.304Z","dateUpdated":"2025-10-09T14:33:13.151Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Snapdragon Wired Infrastructure and Networking"],"product":"Snapdragon","vendor":"Qualcomm, Inc.","versions":[{"status":"affected","version":"CSR8811"},{"status":"affected","version":"Immersive Home 214 Platform"},{"status":"affected","version":"Immersive Home 216 Platform"},{"status":"affected","version":"Immersive Home 316 Platform"},{"status":"affected","version":"Immersive Home 318 Platform"},{"status":"affected","version":"IPQ5010"},{"status":"affected","version":"IPQ5028"},{"status":"affected","version":"IPQ8070"},{"status":"affected","version":"IPQ8070A"},{"status":"affected","version":"IPQ8071"},{"status":"affected","version":"IPQ8071A"},{"status":"affected","version":"IPQ8072"},{"status":"affected","version":"IPQ8072A"},{"status":"affected","version":"IPQ8074"},{"status":"affected","version":"IPQ8074A"},{"status":"affected","version":"IPQ8076"},{"status":"affected","version":"IPQ8076A"},{"status":"affected","version":"IPQ8078"},{"status":"affected","version":"IPQ8078A"},{"status":"affected","version":"IPQ8173"},{"status":"affected","version":"IPQ8174"},{"status":"affected","version":"IPQ9008"},{"status":"affected","version":"IPQ9574"},{"status":"affected","version":"PMP8074"},{"status":"affected","version":"QCA4024"},{"status":"affected","version":"QCA6428"},{"status":"affected","version":"QCA6438"},{"status":"affected","version":"QCA6694"},{"status":"affected","version":"QCA8072"},{"status":"affected","version":"QCA8075"},{"status":"affected","version":"QCA8081"},{"status":"affected","version":"QCA9888"},{"status":"affected","version":"QCA9889"},{"status":"affected","version":"QCA9984"},{"status":"affected","version":"QCN5022"},{"status":"affected","version":"QCN5024"},{"status":"affected","version":"QCN5052"},{"status":"affected","version":"QCN5054"},{"status":"affected","version":"QCN5064"},{"status":"affected","version":"QCN5122"},{"status":"affected","version":"QCN5124"},{"status":"affected","version":"QCN5152"},{"status":"affected","version":"QCN5154"},{"status":"affected","version":"QCN5164"},{"status":"affected","version":"QCN5550"},{"status":"affected","version":"QCN6023"},{"status":"affected","version":"QCN6024"},{"status":"affected","version":"QCN6100"},{"status":"affected","version":"QCN6102"},{"status":"affected","version":"QCN6112"},{"status":"affected","version":"QCN6122"},{"status":"affected","version":"QCN6132"},{"status":"affected","version":"QCN9000"},{"status":"affected","version":"QCN9001"},{"status":"affected","version":"QCN9002"},{"status":"affected","version":"QCN9003"},{"status":"affected","version":"QCN9012"},{"status":"affected","version":"QCN9022"},{"status":"affected","version":"QCN9024"},{"status":"affected","version":"QCN9070"},{"status":"affected","version":"QCN9072"},{"status":"affected","version":"QCN9074"},{"status":"affected","version":"QCN9100"},{"status":"affected","version":"QCN9274"},{"status":"affected","version":"SDX55"}]}],"descriptions":[{"lang":"en","value":"Information disclosure may occur while processing the hypervisor log."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"2cfc7d3e-20d3-47ac-8db7-1b7285aff15f","shortName":"qualcomm","dateUpdated":"2025-10-09T03:17:54.304Z"},"references":[{"url":"https://docs.qualcomm.com/product/publicresources/securitybulletin/october-2025-bulletin.html"}],"title":"Improper Input Validation in TZ Firmware"},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-09T14:26:59.519511Z","id":"CVE-2025-27040","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-09T14:33:13.151Z"}}]}}