7.8

CVE-2020-11121

u'Possible buffer overflow in WIFI hal process due to usage of memcpy without checking length of destination buffer' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile in QCM4290, QCS4290, QM215, QSM8350, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SC8180X, SC8180XP, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6250, SM6350, SM7125, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P

Data is provided by the National Vulnerability Database (NVD)
QualcommQcm4290 Firmware Version-
   QualcommQcm4290 Version-
QualcommQcs4290 Firmware Version-
   QualcommQcs4290 Version-
QualcommQm215 Firmware Version-
   QualcommQm215 Version-
QualcommQsm8350 Firmware Version-
   QualcommQsm8350 Version-
QualcommSa6145p Firmware Version-
   QualcommSa6145p Version-
QualcommSa6155 Firmware Version-
   QualcommSa6155 Version-
QualcommSa6155p Firmware Version-
   QualcommSa6155p Version-
QualcommSa8155 Firmware Version-
   QualcommSa8155 Version-
QualcommSa8155p Firmware Version-
   QualcommSa8155p Version-
QualcommSc8180x Firmware Version-
   QualcommSc8180x Version-
QualcommSc8180xp Firmware Version-
   QualcommSc8180xp Version-
QualcommSdx55 Firmware Version-
   QualcommSdx55 Version-
QualcommSdx55m Firmware Version-
   QualcommSdx55m Version-
QualcommSm4250 Firmware Version-
   QualcommSm4250 Version-
QualcommSm4250p Firmware Version-
   QualcommSm4250p Version-
QualcommSm6115 Firmware Version-
   QualcommSm6115 Version-
QualcommSm6115p Firmware Version-
   QualcommSm6115p Version-
QualcommSm6125 Firmware Version-
   QualcommSm6125 Version-
QualcommSm6250 Firmware Version-
   QualcommSm6250 Version-
QualcommSm6350 Firmware Version-
   QualcommSm6350 Version-
QualcommSm7125 Firmware Version-
   QualcommSm7125 Version-
QualcommSm7225 Firmware Version-
   QualcommSm7225 Version-
QualcommSm7250 Firmware Version-
   QualcommSm7250 Version-
QualcommSm7250p Firmware Version-
   QualcommSm7250p Version-
QualcommSm8150 Firmware Version-
   QualcommSm8150 Version-
QualcommSm8150p Firmware Version-
   QualcommSm8150p Version-
QualcommSm8250 Firmware Version-
   QualcommSm8250 Version-
QualcommSm8350 Firmware Version-
   QualcommSm8350 Version-
QualcommSm8350p Firmware Version-
   QualcommSm8350p Version-
QualcommSxr2130 Firmware Version-
   QualcommSxr2130 Version-
QualcommSxr2130p Firmware Version-
   QualcommSxr2130p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.137
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.