CVE-2021-32025 - CVE House
Back to Database
Status published High CVE-2021-32025

An elevation of privilege vulnerability in the QNX Neutrino Kernel...

Vulnerability Description

An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX OS for Medical version 2.0.0 could allow an attacker to potentially access data, modify behavior, or permanently crash the system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-32025

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

QNX Software Development Platform (SDP), QNX OS for Medical (QOSM), and QNX OS for Safety (QOS)
Vulnerable Versions:
QNX SDP 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2 safety products compliant with IEC 61508 and/or ISO 26262, QNX OS for Safety versions 2.0.0 to 2.0.1 safety products compliant with IEC 61508 and/or ISO 26262, QNX OS for Medical versions 1.0.0 to 1.1.1 safety products compliant with IEC 62304, QNX OS for Medical versions 2.0.0 safety product compliant with IEC 62304

Timeline

Official Publish: March 9th, 2022
Last Modified: August 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.