CVE-2025-21472 Details
Description
Information disclosure while capturing logs as eSE debug messages are logged.
A vulnerability allowing information disclosure has been identified in various chipsets of Qualcomm Snapdragon processors. This issue arises from leftover debug code in the secure element (eSE), which can lead to the unintentional exposure of sensitive information. The vulnerability is present in chipsets such as the Snapdragon 8 Gen 1 Mobile Platform, Snapdragon 865 5G Mobile Platform, and several others. The issue is rated medium in severity.
Qualcomm has notified customers about this vulnerability and provided patching instructions. The specific patch can be found in the Qualcomm August 2025 Security Bulletin.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.qualcomm.com/product/publicresources/securitybulletin/august-2025-bulletin.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-489 | Active Debug Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qualcomm fastconnect 6900 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 6900 | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 firmware | All versions |
CPE
Remediation
| |
| qualcomm fastconnect 7800 | All versions |
CPE
Remediation
| |
| qualcomm qca9367 firmware | All versions |
CPE
Remediation
| |
| qualcomm qca9367 | All versions |
CPE
Remediation
| |
| qualcomm qca9377 firmware | All versions |
CPE
Remediation
| |
| qualcomm qca9377 | All versions |
CPE
Remediation
| |
| qualcomm qcs8550 firmware | All versions |
CPE
Remediation
| |
| qualcomm qcs8550 | All versions |
CPE
Remediation
| |
| qualcomm sa8530p firmware | All versions |
CPE
Remediation
| |
| qualcomm sa8530p | All versions |
CPE
Remediation
| |
| qualcomm sa8540p firmware | All versions |
CPE
Remediation
| |
| qualcomm sa8540p | All versions |
CPE
Remediation
| |
| qualcomm sa9000p firmware | All versions |
CPE
Remediation
| |
| qualcomm sa9000p | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 1 mobile platform firmware | All versions |
CPE
Remediation
| |
| qualcomm snapdragon 8 gen 1 mobile platform | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 firmware | All versions |
CPE
Remediation
| |
| qualcomm wcd9380 | All versions |
CPE
Remediation
| |
| qualcomm wsa8830 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8830 | All versions |
CPE
Remediation
| |
| qualcomm wsa8835 firmware | All versions |
CPE
Remediation
| |
| qualcomm wsa8835 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 18, 2025 | Initial Analysis | [email protected] |
| Aug 6, 2025 | New CVE Received | [email protected] |