Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Conclusion & alert: CVE-2023-21626 is rated Low Risk (33.8/100): CVSS High severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.03% | 0.05% | +0.02% |
| 2 | 2025-11-18 | 0.05% | 0.03% | -0.02% |
| 3 | 2025-03-19 | — | 0.05% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.1 | 3.1 | HIGH |
|
1.8 | 5.2 | [email protected] |
| 7.1 | 3.1 | HIGH |
|
1.8 | 5.2 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| qualcomm | apq8009_firmware | — | cpe:2.3:o:qualcomm:apq8009_firmware:-:*:*:*:*:*:*:* |
| qualcomm | apq8017_firmware | — | cpe:2.3:o:qualcomm:apq8017_firmware:-:*:*:*:*:*:*:* |
| qualcomm | apq8037_firmware | — | cpe:2.3:o:qualcomm:apq8037_firmware:-:*:*:*:*:*:*:* |
| qualcomm | aqt1000_firmware | — | cpe:2.3:o:qualcomm:aqt1000_firmware:-:*:*:*:*:*:*:* |
| qualcomm | ar8035_firmware | — | cpe:2.3:o:qualcomm:ar8035_firmware:-:*:*:*:*:*:*:* |
| qualcomm | csra6620_firmware | — | cpe:2.3:o:qualcomm:csra6620_firmware:-:*:*:*:*:*:*:* |
| qualcomm | csra6640_firmware | — | cpe:2.3:o:qualcomm:csra6640_firmware:-:*:*:*:*:*:*:* |
| qualcomm | csrb31024_firmware | — | cpe:2.3:o:qualcomm:csrb31024_firmware:-:*:*:*:*:*:*:* |
| qualcomm | fsm10056_firmware | — | cpe:2.3:o:qualcomm:fsm10056_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm8207_firmware | — | cpe:2.3:o:qualcomm:mdm8207_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9205_firmware | — | cpe:2.3:o:qualcomm:mdm9205_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9206_firmware | — | cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9207_firmware | — | cpe:2.3:o:qualcomm:mdm9207_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9607_firmware | — | cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9628_firmware | — | cpe:2.3:o:qualcomm:mdm9628_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8108_firmware | — | cpe:2.3:o:qualcomm:msm8108_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8208_firmware | — | cpe:2.3:o:qualcomm:msm8208_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8209_firmware | — | cpe:2.3:o:qualcomm:msm8209_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8608_firmware | — | cpe:2.3:o:qualcomm:msm8608_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8917_firmware | — | cpe:2.3:o:qualcomm:msm8917_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8920_firmware | — | cpe:2.3:o:qualcomm:msm8920_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8937_firmware | — | cpe:2.3:o:qualcomm:msm8937_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8940_firmware | — | cpe:2.3:o:qualcomm:msm8940_firmware:-:*:*:*:*:*:*:* |
| qualcomm | pm8937_firmware | — | cpe:2.3:o:qualcomm:pm8937_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qam8295p_firmware | — | cpe:2.3:o:qualcomm:qam8295p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca4004_firmware | — | cpe:2.3:o:qualcomm:qca4004_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca4020_firmware | — | cpe:2.3:o:qualcomm:qca4020_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6174a_firmware | — | cpe:2.3:o:qualcomm:qca6174a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6310_firmware | — | cpe:2.3:o:qualcomm:qca6310_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6320_firmware | — | cpe:2.3:o:qualcomm:qca6320_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6335_firmware | — | cpe:2.3:o:qualcomm:qca6335_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6390_firmware | — | cpe:2.3:o:qualcomm:qca6390_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6391_firmware | — | cpe:2.3:o:qualcomm:qca6391_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6420_firmware | — | cpe:2.3:o:qualcomm:qca6420_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6421_firmware | — | cpe:2.3:o:qualcomm:qca6421_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6426_firmware | — | cpe:2.3:o:qualcomm:qca6426_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6430_firmware | — | cpe:2.3:o:qualcomm:qca6430_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6431_firmware | — | cpe:2.3:o:qualcomm:qca6431_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6436_firmware | — | cpe:2.3:o:qualcomm:qca6436_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6564_firmware | — | cpe:2.3:o:qualcomm:qca6564_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6564a_firmware | — | cpe:2.3:o:qualcomm:qca6564a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6564au_firmware | — | cpe:2.3:o:qualcomm:qca6564au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574_firmware | — | cpe:2.3:o:qualcomm:qca6574_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574a_firmware | — | cpe:2.3:o:qualcomm:qca6574a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574au_firmware | — | cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6595_firmware | — | cpe:2.3:o:qualcomm:qca6595_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6595au_firmware | — | cpe:2.3:o:qualcomm:qca6595au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6696_firmware | — | cpe:2.3:o:qualcomm:qca6696_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca8081_firmware | — | cpe:2.3:o:qualcomm:qca8081_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca8337_firmware | — | cpe:2.3:o:qualcomm:qca8337_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca9367_firmware | — | cpe:2.3:o:qualcomm:qca9367_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca9377_firmware | — | cpe:2.3:o:qualcomm:qca9377_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca9379_firmware | — | cpe:2.3:o:qualcomm:qca9379_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm2290_firmware | — | cpe:2.3:o:qualcomm:qcm2290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm4290_firmware | — | cpe:2.3:o:qualcomm:qcm4290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm6125_firmware | — | cpe:2.3:o:qualcomm:qcm6125_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm6490_firmware | — | cpe:2.3:o:qualcomm:qcm6490_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcn7606_firmware | — | cpe:2.3:o:qualcomm:qcn7606_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs2290_firmware | — | cpe:2.3:o:qualcomm:qcs2290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs405_firmware | — | cpe:2.3:o:qualcomm:qcs405_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs410_firmware | — | cpe:2.3:o:qualcomm:qcs410_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs4290_firmware | — | cpe:2.3:o:qualcomm:qcs4290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs603_firmware | — | cpe:2.3:o:qualcomm:qcs603_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs605_firmware | — | cpe:2.3:o:qualcomm:qcs605_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs610_firmware | — | cpe:2.3:o:qualcomm:qcs610_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs6125_firmware | — | cpe:2.3:o:qualcomm:qcs6125_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs6490_firmware | — | cpe:2.3:o:qualcomm:qcs6490_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs8155_firmware | — | cpe:2.3:o:qualcomm:qcs8155_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcx315_firmware | — | cpe:2.3:o:qualcomm:qcx315_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qsm8350_firmware | — | cpe:2.3:o:qualcomm:qsm8350_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qm215_firmware | — | cpe:2.3:o:qualcomm:qm215_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa4150p_firmware | — | cpe:2.3:o:qualcomm:sa4150p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa4155p_firmware | — | cpe:2.3:o:qualcomm:sa4155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa415m_firmware | — | cpe:2.3:o:qualcomm:sa415m_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa515m_firmware | — | cpe:2.3:o:qualcomm:sa515m_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6145p_firmware | — | cpe:2.3:o:qualcomm:sa6145p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6150p_firmware | — | cpe:2.3:o:qualcomm:sa6150p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6155_firmware | — | cpe:2.3:o:qualcomm:sa6155_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6155p_firmware | — | cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8145p_firmware | — | cpe:2.3:o:qualcomm:sa8145p_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.qualcomm.com/company/product-security/bulletins/august-2023-bulletin | Vendor Advisory |