CVE-2026-24078: Exposure of Private Personal Information to an Unauthorized Actor in Data Modem
Published Aug 4, 2026
·Updated
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
Event History
Aug 4, 2026
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-24078?
CVE-2026-24078 has a medium severity rating of 6.5.
2
What type of vulnerability is CVE-2026-24078?
CVE-2026-24078 is an information disclosure vulnerability that exposes private personal information.
3
How does CVE-2026-24078 occur?
CVE-2026-24078 occurs when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
4
What are the potential impacts of CVE-2026-24078?
The potential impact of CVE-2026-24078 includes unauthorized access to private personal information.
5
How can I protect against CVE-2026-24078?
To protect against CVE-2026-24078, ensure proper IPSec negotiation and establish secure SIP signaling during NG-eCall.