CVE-2025-47389 is a memory corruption vulnerability affecting attestation report generation functionality, arising from an integer overflow condition that causes buffer copy operations to fail improperly. The vulnerability requires local access with low-level user privileges to exploit, but carries high severity with potential for complete compromise of confidentiality, integrity, and availability on affected systems (CVSS 7.8). The attack vector is local with low complexity, making exploitation relatively straightforward once an attacker gains initial system access. Regarding exploitation status, this vulnerability is not currently being exploited in the wild, has not been added to the KEV catalogue, and shows minimal community attention with an EPSS score of 0.000060 indicating rare overall CVE prevalence. While not an immediate active threat, the moderate FAUCET risk score of 49.0 suggests organizations should prioritize patching during regular maintenance cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:ar8035_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:csra6620_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:csra6640_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.