Qualcomm plctool Vulnerability Allows Local Attacker with Low Privileges to Gain Root Access
CVE-2024-26002
7.8HIGH
What is CVE-2024-26002?
An improper input validation vulnerability exists in Qualcomm's PLCTool, which can be exploited by a local attacker with low privileges. By changing the ownership of certain files, an attacker can escalate their privileges to root level, potentially compromising the system's integrity and security. This vulnerability highlights the importance of robust input validation to prevent unauthorized access and maintain system security.
Affected Version(s)
CHARX SEC-3000 0 <= 1.5.0
CHARX SEC-3050 0 <= 1.5.0
CHARX SEC-3100 0 <= 1.5.0