MEDIUM · 6.5

CVE-2025-47370

Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.

Vulnerability Description

Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
QualcommAr8035 Firmware-
QualcommAr8035-
QualcommCsrb31024 Firmware-
QualcommCsrb31024-
QualcommFastconnect 6700 Firmware-
QualcommFastconnect 6700-
QualcommFastconnect 6900 Firmware-
QualcommFastconnect 6900-
QualcommFastconnect 7800 Firmware-
QualcommFastconnect 7800-
QualcommSm8550P Firmware-
QualcommSm8550P-
QualcommSm8635 Firmware-
QualcommSm8635-
QualcommSm8635P Firmware-
QualcommSm8635P-
QualcommSm8650Q Firmware-
QualcommSm8650Q-
QualcommSm8735 Firmware-
QualcommSm8735-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-47370?

CVE-2025-47370 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.

How severe is CVE-2025-47370?

CVE-2025-47370 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-47370?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Ar8035 Firmware, Qualcomm Ar8035, Qualcomm Csrb31024 Firmware, Qualcomm Csrb31024, Qualcomm Fastconnect 6700 Firmware.