8.8
CVE-2020-11257
- EPSS 0.04%
- Published 09.06.2021 05:15:07
- Last modified 21.11.2024 04:57:31
- Source product-security@qualcomm.com
- Teams watchlist Login
- Open Login
Memory corruption due to lack of validation of pointer arguments passed to TrustZone BSP in Snapdragon Wired Infrastructure and Networking
Data is provided by the National Vulnerability Database (NVD)
Qualcomm ≫ Ar7420 Firmware Version-
Qualcomm ≫ Ar9580 Firmware Version-
Qualcomm ≫ Csr8811 Firmware Version-
Qualcomm ≫ Ipq4018 Firmware Version-
Qualcomm ≫ Ipq4019 Firmware Version-
Qualcomm ≫ Ipq4028 Firmware Version-
Qualcomm ≫ Ipq4029 Firmware Version-
Qualcomm ≫ Qca10901 Firmware Version-
Qualcomm ≫ Qca4024 Firmware Version-
Qualcomm ≫ Qca7500 Firmware Version-
Qualcomm ≫ Qca7520 Firmware Version-
Qualcomm ≫ Qca7550 Firmware Version-
Qualcomm ≫ Qca8075 Firmware Version-
Qualcomm ≫ Qca9880 Firmware Version-
Qualcomm ≫ Qca9886 Firmware Version-
Qualcomm ≫ Qca9888 Firmware Version-
Qualcomm ≫ Qca9889 Firmware Version-
Qualcomm ≫ Qca9898 Firmware Version-
Qualcomm ≫ Qca9984 Firmware Version-
Qualcomm ≫ Qca9992 Firmware Version-
Qualcomm ≫ Qca9994 Firmware Version-
Qualcomm ≫ Qcn3018 Firmware Version-
Qualcomm ≫ Qfe1922 Firmware Version-
Qualcomm ≫ Qfe1952 Firmware Version-
Qualcomm ≫ Wcd9340 Firmware Version-
Qualcomm ≫ Wsa8810 Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.083 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.