Lucene search

K
cveQualcommCVE-2020-11208
HistoryNov 12, 2020 - 10:15 a.m.

CVE-2020-11208

2020-11-1210:15:13
CWE-191
qualcomm
web.nvd.nist.gov
33
cve-2020-11208
out of bound issue
dsp services
qualcomm snapdragon
vulnerability
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

39.4%

Out of Bound issue in DSP services while processing received arguments due to improper validation of length received as an argument’ in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439

Affected configurations

Nvd
Node
qualcommsd820_firmwareMatch-
AND
qualcommsd820Match-
Node
qualcommsd821_firmwareMatch-
AND
qualcommsd821Match-
Node
qualcommqcs603_firmwareMatch-
AND
qualcommqcs603Match-
Node
qualcommqcs605_firmwareMatch-
AND
qualcommqcs605Match-
Node
qualcommsda855_firmwareMatch-
AND
qualcommsda855Match-
Node
qualcommsa6155p_firmwareMatch-
AND
qualcommsa6155pMatch-
Node
qualcommsa6145p_firmwareMatch-
AND
qualcommsa6145pMatch-
Node
qualcommsa6155_firmwareMatch-
AND
qualcommsa6155Match-
Node
qualcommsa6155p_firmwareMatch-
AND
qualcommsa6155pMatch-
Node
qualcommsd855_firmwareMatch-
AND
qualcommsd855Match-
Node
qualcommsd675_firmwareMatch-
AND
qualcommsd675Match-
Node
qualcommsd660_firmwareMatch-
AND
qualcommsd660Match-
Node
qualcommsd429_firmwareMatch-
AND
qualcommsd429Match-
Node
qualcommsd439_firmwareMatch-
AND
qualcommsd439Match-
VendorProductVersionCPE
qualcommsd820_firmware-cpe:2.3:o:qualcomm:sd820_firmware:-:*:*:*:*:*:*:*
qualcommsd820-cpe:2.3:h:qualcomm:sd820:-:*:*:*:*:*:*:*
qualcommsd821_firmware-cpe:2.3:o:qualcomm:sd821_firmware:-:*:*:*:*:*:*:*
qualcommsd821-cpe:2.3:h:qualcomm:sd821:-:*:*:*:*:*:*:*
qualcommqcs603_firmware-cpe:2.3:o:qualcomm:qcs603_firmware:-:*:*:*:*:*:*:*
qualcommqcs603-cpe:2.3:h:qualcomm:qcs603:-:*:*:*:*:*:*:*
qualcommqcs605_firmware-cpe:2.3:o:qualcomm:qcs605_firmware:-:*:*:*:*:*:*:*
qualcommqcs605-cpe:2.3:h:qualcomm:qcs605:-:*:*:*:*:*:*:*
qualcommsda855_firmware-cpe:2.3:o:qualcomm:sda855_firmware:-:*:*:*:*:*:*:*
qualcommsda855-cpe:2.3:h:qualcomm:sda855:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CNA Affected

[
  {
    "product": "Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile",
    "vendor": "Qualcomm, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

39.4%

Related for CVE-2020-11208