Dell update for Qualcomm Camera driver



Risk Low
Patch available YES
Number of vulnerabilities 4
CVE-ID CVE-2025-21447
CVE-2025-21462
CVE-2025-21469
CVE-2025-21470
CWE-ID CWE-129
CWE-787
CWE-284
Exploitation vector Local
Public exploit N/A
Vulnerable software
XPS 13 9345
Hardware solutions / Firmware

Qualcomm MIPI Camera Driver
Hardware solutions / Drivers

Vendor Dell

Security Bulletin

This security bulletin contains information about 4 vulnerabilities.

1) Improper Validation of Array Index

EUVDB-ID: #VU107104

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21447

CWE-ID: CWE-129 - Improper Validation of Array Index

Exploit availability: No

Description

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Computer Vision. A local application can execute arbitrary code.

Mitigation

Install update from vendor's website.

Vulnerable software versions

XPS 13 9345: All versions

Qualcomm MIPI Camera Driver: before 1.1.0.54

CPE2.3 External links

https://www.dell.com/support/kbdoc/nl-nl/000299519/dsa-2025-148


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Out-of-bounds write

EUVDB-ID: #VU108704

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21462

CWE-ID: CWE-787 - Out-of-bounds write

Exploit availability: No

Description

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Computer Vision. A local application can execute arbitrary code.

Mitigation

Install update from vendor's website.

Vulnerable software versions

XPS 13 9345: All versions

Qualcomm MIPI Camera Driver: before 1.1.0.54

CPE2.3 External links

https://www.dell.com/support/kbdoc/nl-nl/000299519/dsa-2025-148


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Improper Access Control

EUVDB-ID: #VU108705

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21469

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Camera Driver. A local application can execute arbitrary code.

Mitigation

Install update from vendor's website.

Vulnerable software versions

XPS 13 9345: All versions

Qualcomm MIPI Camera Driver: before 1.1.0.54

CPE2.3 External links

https://www.dell.com/support/kbdoc/nl-nl/000299519/dsa-2025-148


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Improper Access Control

EUVDB-ID: #VU108706

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21470

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Camera Driver. A local application can execute arbitrary code.

Mitigation

Install update from vendor's website.

Vulnerable software versions

XPS 13 9345: All versions

Qualcomm MIPI Camera Driver: before 1.1.0.54

CPE2.3 External links

https://www.dell.com/support/kbdoc/nl-nl/000299519/dsa-2025-148


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###