← Vulnerability feed

Vulnerability record · CVE-2021-32025 · published 10 March 2022

CVE-2021-32025: Blackberry qnx momentics vulnerability

Blackberry · Qnx Momentics

An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX OS for Medical version 2.0.0 could allow an attacker to potentially access data, modify behavior, or permanently crash the system.

7.8 CVSS 3.1 High EPSS 0.18% · top 93.7% CWE-368 · CWE-368
7.8CVSS 3.1 base score, v2 7.2
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX OS for Medical version 2.0.0 could allow an attacker to potentially access data, modify behavior, or permanently crash the system.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32025 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-2474Blackberry qnx software development platform out-of-bounds write vulnerabilityOut-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service …EPSS 0.73%9.8CVE-2024-48856Blackberry qnx software development platform out-of-bounds write vulnerabilityOut-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service …EPSS 0.62%9.8CVE-2021-32024Blackberry qnx software development platform vulnerabilityA remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execu…EPSS 1.8%9.8CVE-2021-22156Blackberry qnx software development platform integer overflow vulnerabilityAn integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Plat…EPSS 1.8%9.8CVE-2020-6932Blackberry qnx software development platform vulnerabilityAn information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versi…EPSS 3.6%9.6CVE-2017-3891Blackberry qnx software development platform incorrect authorization vulnerabilityIn BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with…EPSS 1.3%9.3CVE-2008-3024Blackberry qnx momentics out-of-bounds write vulnerabilityStack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename i…EPSS 5.9%9.0CVE-2024-35213Blackberry qnx software development platform vulnerabilityAn improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially caus…EPSS 0.52%

Source: NIST National Vulnerability Database (record CVE-2021-32025), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.