CVE-2020-11117
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 19.68% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- qualcomm/ipq4019 firmware · qualcomm/ipq6018 firmware · qualcomm/ipq8064 firmware · qualcomm/ipq8074 firmware · qualcomm/qca4531 firmware · qualcomm/qca9531 firmware · qualcomm/qca9980 firmware
- Source
- product-security@qualcomm.com
References
- https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletinBroken Link
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1065Exploit, Third Party Advisory
- https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletinBroken Link
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1065Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.