SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11117

u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired…

CRITICAL 9.8EPSS 19.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 19.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
19.68% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-77
Affected
qualcomm/ipq4019 firmware · qualcomm/ipq6018 firmware · qualcomm/ipq8064 firmware · qualcomm/ipq8074 firmware · qualcomm/qca4531 firmware · qualcomm/qca9531 firmware · qualcomm/qca9980 firmware
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.