7.8

CVE-2020-11201

Exploit

Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA845, SDM640, SDM830, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM8150, SM8150P

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommQcm6125 Firmware Version-
   QualcommQcm6125 Version-
QualcommQcs410 Firmware Version-
   QualcommQcs410 Version-
QualcommQcs603 Firmware Version-
   QualcommQcs603 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommQcs610 Firmware Version-
   QualcommQcs610 Version-
QualcommQcs6125 Firmware Version-
   QualcommQcs6125 Version-
QualcommSa6145p Firmware Version-
   QualcommSa6145p Version-
QualcommSa6155 Firmware Version-
   QualcommSa6155 Version-
QualcommSa6155p Firmware Version-
   QualcommSa6155p Version-
QualcommSa8155 Firmware Version-
   QualcommSa8155 Version-
QualcommSa8155p Firmware Version-
   QualcommSa8155p Version-
QualcommSda640 Firmware Version-
   QualcommSda640 Version-
QualcommSda845 Firmware Version-
   QualcommSda845 Version-
QualcommSdm640 Firmware Version-
   QualcommSdm640 Version-
QualcommSdm830 Firmware Version-
   QualcommSdm830 Version-
QualcommSdm845 Firmware Version-
   QualcommSdm845 Version-
QualcommSdx50m Firmware Version-
   QualcommSdx50m Version-
QualcommSdx55 Firmware Version-
   QualcommSdx55 Version-
QualcommSdx55m Firmware Version-
   QualcommSdx55m Version-
QualcommSm6125 Firmware Version-
   QualcommSm6125 Version-
QualcommSm6150 Firmware Version-
   QualcommSm6150 Version-
QualcommSm6250 Firmware Version-
   QualcommSm6250 Version-
QualcommSm6250p Firmware Version-
   QualcommSm6250p Version-
QualcommSm7125 Firmware Version-
   QualcommSm7125 Version-
QualcommSm7150 Firmware Version-
   QualcommSm7150 Version-
QualcommSm7150p Firmware Version-
   QualcommSm7150p Version-
QualcommSm8150 Firmware Version-
   QualcommSm8150 Version-
QualcommSm8150p Firmware Version-
   QualcommSm8150p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.162
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.