SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11198

Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

MEDIUM 6.7EPSS 0.13%

Does this matter?

Lower severity and a low EPSS score (0.13%). Track it; it rarely justifies an emergency change on its own.

Description

Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.13% probability · 2th percentile
CISA KEV
Not listed
Weakness
CWE-212
Affected
qualcomm/aqt1000 firmware · qualcomm/ar8031 firmware · qualcomm/ar8035 firmware · qualcomm/csr8811 firmware · qualcomm/csra6620 firmware · qualcomm/csra6640 firmware · qualcomm/csrb31024 firmware · qualcomm/fsm10055 firmware · qualcomm/fsm10056 firmware · qualcomm/ipq6000 firmware · qualcomm/ipq6005 firmware · qualcomm/ipq6010 firmware · qualcomm/ipq6018 firmware · qualcomm/ipq6028 firmware · qualcomm/pm3003a firmware · qualcomm/pm4125 firmware · qualcomm/pm4250 firmware · qualcomm/pm456 firmware · qualcomm/pm6125 firmware · qualcomm/pm6150 firmware · +40 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.