7.8

CVE-2020-11202

Exploit

Buffer overflow/underflow occurs when typecasting the buffer passed by CPU internally in the library which is not aligned with the actual size of the structure' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA670, SDA845, SDM640, SDM670, SDM710, SDM830, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM8150, SM8150P

Data is provided by the National Vulnerability Database (NVD)
QualcommQcm6125 Firmware Version-
   QualcommQcm6125 Version-
QualcommQcs410 Firmware Version-
   QualcommQcs410 Version-
QualcommQcs603 Firmware Version-
   QualcommQcs603 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommQcs610 Firmware Version-
   QualcommQcs610 Version-
QualcommQcs6125 Firmware Version-
   QualcommQcs6125 Version-
QualcommSa6145p Firmware Version-
   QualcommSa6145p Version-
QualcommSa6155 Firmware Version-
   QualcommSa6155 Version-
QualcommSa6155p Firmware Version-
   QualcommSa6155p Version-
QualcommSa8155 Firmware Version-
   QualcommSa8155 Version-
QualcommSa8155p Firmware Version-
   QualcommSa8155p Version-
QualcommSda640 Firmware Version-
   QualcommSda640 Version-
QualcommSda670 Firmware Version-
   QualcommSda670 Version-
QualcommSda845 Firmware Version-
   QualcommSda845 Version-
QualcommSdm640 Firmware Version-
   QualcommSdm640 Version-
QualcommSdm670 Firmware Version-
   QualcommSdm670 Version-
QualcommSdm710 Firmware Version-
   QualcommSdm710 Version-
QualcommSdm830 Firmware Version-
   QualcommSdm830 Version-
QualcommSdm845 Firmware Version-
   QualcommSdm845 Version-
QualcommSdx50m Firmware Version-
   QualcommSdx50m Version-
QualcommSdx55 Firmware Version-
   QualcommSdx55 Version-
QualcommSdx55m Firmware Version-
   QualcommSdx55m Version-
QualcommSm6125 Firmware Version-
   QualcommSm6125 Version-
QualcommSm6150 Firmware Version-
   QualcommSm6150 Version-
QualcommSm6150p Firmware Version-
   QualcommSm6150p Version-
QualcommSm6250 Firmware Version-
   QualcommSm6250 Version-
QualcommSm6250p Firmware Version-
   QualcommSm6250p Version-
QualcommSm7125 Firmware Version-
   QualcommSm7125 Version-
QualcommSm7150 Firmware Version-
   QualcommSm7150 Version-
QualcommSm7150p Firmware Version-
   QualcommSm7150p Version-
QualcommSm8150 Firmware Version-
   QualcommSm8150 Version-
QualcommSm8150p Firmware Version-
   QualcommSm8150p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.19
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.