9.8

CVE-2020-11117

Exploit

u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980

Data is provided by the National Vulnerability Database (NVD)
QualcommIpq4019 Firmware Version-
   QualcommIpq4019 Version-
QualcommIpq6018 Firmware Version-
   QualcommIpq6018 Version-
QualcommIpq8064 Firmware Version-
   QualcommIpq8064 Version-
QualcommIpq8074 Firmware Version-
   QualcommIpq8074 Version-
QualcommQca4531 Firmware Version-
   QualcommQca4531 Version-
QualcommQca9531 Firmware Version-
   QualcommQca9531 Version-
QualcommQca9980 Firmware Version-
   QualcommQca9980 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.59% 0.873
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.