Vulnerability Description
Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Denx | U-Boot | < 2017.11 |
| Qualcomm | Ipq4019 | - |
| Qualcomm | Ipq5018 | - |
| Qualcomm | Ipq5322 | - |
| Qualcomm | Ipq6018 | - |
| Qualcomm | Ipq8064 | - |
| Qualcomm | Ipq8074 | - |
| Qualcomm | Ipq9574 | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-343-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2025-24857?
CVE-2025-24857 is a vulnerability with a CVSS score of 7.6 (HIGH). Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 c...
How severe is CVE-2025-24857?
CVE-2025-24857 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24857?
Check the references section above for vendor advisories and patch information. Affected products include: Denx U-Boot, Qualcomm Ipq4019, Qualcomm Ipq5018, Qualcomm Ipq5322, Qualcomm Ipq6018.