Qualcomm NG-eCall IPSec Negotiation Info Disclosure
CVE-2026-24078 Published on August 4, 2026

Exposure of Private Personal Information to an Unauthorized Actor in Data Modem
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

What is a Privacy violation Vulnerability?

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

CVE-2026-24078 has been classified to as a Privacy violation vulnerability or weakness.


Products Associated with CVE-2026-24078

Want to know whenever a new CVE is published for Qualcomm Snapdragon? stack.watch will email you.

 

Affected Versions

Qualcomm, Inc. Snapdragon: