LiveActive security incident?Get immediate response
CVE Record

CVE-2014-4325: The cmd_boot function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualco...

The cmd_boot function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to bypass intended device-lock and kernel-signature restrictions by using fastboot mode in a boot command for an arbitrary kernel image.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This is a bootloader trust failure. On affected LK bootloader builds distributed with Qualcomm Android contributions, fastboot could bypass device-lock and kernel-signature restrictions to boot an arbitrary kernel image. That can undermine device integrity, especially where physical or maintenance-mode access is possible.

Executive priority

Prioritize this for managed fleets containing older Qualcomm/MSM Android or embedded devices. Urgency depends on whether affected bootloader builds are present and whether attackers can reach fastboot mode. Lack of version detail means inventory work is the first decision point.

Technical view

CVE-2014-4325 affects the cmd_boot function in app/aboot/aboot.c in the Little Kernel bootloader as distributed with QuIC Android contributions for MSM devices and other products. The issue allows bypass of intended lock and signature checks through the fastboot boot path.

Likely exposure

Exposure is most likely in Android devices or embedded products using affected LK aboot code from Qualcomm/QuIC MSM-related distributions. The bundle does not identify exact vendors, models, versions, or CPEs.

Exploitation context

The source bundle does not show CISA KEV listing or active exploitation evidence. The described attack requires access to fastboot mode and an arbitrary kernel image, but the provided sources do not define practical prerequisites across device models.

Researcher notes

The key evidence is narrow: cmd_boot in LK aboot bypasses lock and kernel-signature restrictions through fastboot boot. No CVSS, CWE, affected version list, patch level, or exploitation confirmation is included in the provided bundle.

Mitigation direction

  • Check OEM or Qualcomm-derived vendor guidance for fixed bootloader firmware.
  • Update affected device bootloader or full firmware when vendor fixes are available.
  • Restrict physical and maintenance access to managed devices.
  • Disable or lock down fastboot access only where vendor-supported.
  • Treat unmanaged legacy MSM Android devices as higher-risk assets.

Validation and detection

  • Inventory Android or embedded devices using LK aboot or Qualcomm MSM-derived bootloaders.
  • Map device models and bootloader builds to OEM security advisories.
  • Verify whether locked devices enforce kernel signature checks in vendor-supported tests.
  • Review fleet controls for physical access, USB debugging, and fastboot availability.
  • Record devices with no vendor fix as exception-managed risk.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2014-4325 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.