7.8
CVE-2020-11130
- EPSS 0.05%
- Veröffentlicht 12.11.2020 10:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:53
- Quelle product-security@qualcomm.com
- Teams Watchlist Login
- Unerledigt Login
u'Possible buffer overflow in WIFI hal process due to copying data without checking the buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile in QCM4290, QCS4290, QM215, QSM8350, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SC8180X, SC8180XP, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6250, SM6350, SM7125, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Qcm4290 Firmware Version-
Qualcomm ≫ Qcs4290 Firmware Version-
Qualcomm ≫ Qm215 Firmware Version-
Qualcomm ≫ Qsm8350 Firmware Version-
Qualcomm ≫ Sa6145p Firmware Version-
Qualcomm ≫ Sa6155 Firmware Version-
Qualcomm ≫ Sa6155p Firmware Version-
Qualcomm ≫ Sa8155 Firmware Version-
Qualcomm ≫ Sa8155p Firmware Version-
Qualcomm ≫ Sc8180x Firmware Version-
Qualcomm ≫ Sc8180xp Firmware Version-
Qualcomm ≫ Sdx55 Firmware Version-
Qualcomm ≫ Sdx55m Firmware Version-
Qualcomm ≫ Sm4250 Firmware Version-
Qualcomm ≫ Sm4250p Firmware Version-
Qualcomm ≫ Sm6115 Firmware Version-
Qualcomm ≫ Sm6115p Firmware Version-
Qualcomm ≫ Sm6125 Firmware Version-
Qualcomm ≫ Sm6250 Firmware Version-
Qualcomm ≫ Sm6350 Firmware Version-
Qualcomm ≫ Sm7125 Firmware Version-
Qualcomm ≫ Sm7225 Firmware Version-
Qualcomm ≫ Sm7250 Firmware Version-
Qualcomm ≫ Sm7250p Firmware Version-
Qualcomm ≫ Sm8150 Firmware Version-
Qualcomm ≫ Sm8150p Firmware Version-
Qualcomm ≫ Sm8250 Firmware Version-
Qualcomm ≫ Sm8350 Firmware Version-
Qualcomm ≫ Sm8350p Firmware Version-
Qualcomm ≫ Sxr2130 Firmware Version-
Qualcomm ≫ Sxr2130p Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.137 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.