SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11175

u'Use after free issue in Bluetooth transport driver when a method in the object is accessed after the object has been deleted due to improper timer handling.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

HIGH 7.8EPSS 0.20%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

u'Use after free issue in Bluetooth transport driver when a method in the object is accessed after the object has been deleted due to improper timer handling.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8009W, MSM8909W, QCS605, QM215, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA670, SDA855, SDM1000, SDM640, SDM670, SDM710, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6350, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SXR1120, SXR1130, SXR2130, SXR2130P

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.20% probability · 10th percentile
CISA KEV
Not listed
Weakness
CWE-416
Affected
qualcomm/apq8009w firmware · qualcomm/msm8909w firmware · qualcomm/qcs605 firmware · qualcomm/qm215 firmware · qualcomm/sa6155 firmware · qualcomm/sa6155p firmware · qualcomm/sa8155 firmware · qualcomm/sa8155p firmware · qualcomm/sda640 firmware · qualcomm/sda670 firmware · qualcomm/sda855 firmware · qualcomm/sdm1000 firmware · qualcomm/sdm640 firmware · qualcomm/sdm670 firmware · qualcomm/sdm710 firmware · qualcomm/sdm845 firmware · qualcomm/sdx50m firmware · qualcomm/sdx55 firmware · qualcomm/sdx55m firmware · qualcomm/sm6125 firmware · +11 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.