


Perceptive Security
SOC/SIEM Consultancy

Universal Boot Loader (U-Boot)
Published:
9 December 2025 at 12:00:00
Alert date:
9 December 2025 at 18:02:56
Source:
cisa.gov
CISA published an advisory for CVE-2025-24857, a critical vulnerability in Universal Boot Loader (U-Boot) affecting versions prior to 2017.11. The vulnerability involves improper access control for volatile memory containing boot code, allowing arbitrary code execution. Multiple Qualcomm IPQ chips are confirmed affected. The vulnerability has a CVSS v4 score of 8.6 and CVSS v3 score of 8.4, with low attack complexity. While not remotely exploitable, it requires physical access to the device. Konsulko recommends upgrading to U-Boot version v2025.4 or later, while Qualcomm advises affected chip users to contact support. The vulnerability was reported by Harvey Phillips from Amazon Element55.
Technical details
Mitigation steps:
Affected products:
U-Boot
Qualcomm IPQ4019
Qualcomm IPQ5018
Qualcomm IPQ5322
Qualcomm IPQ6018
Qualcomm IPQ8064
Qualcomm IPQ8074
Qualcomm IPQ9574
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-25-343-01
https://github.com/cisagov/CSAF
https://cwe.mitre.org/data/definitions/1274.html
https://www.cve.org/CVERecord?id=CVE-2025-24857
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
https://ftp.denx.de/pub/u-boot/
https://www.qualcomm.com/support/contact
https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
https://www.cisa.gov/topics/industrial-control-systems
https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
