CVE-2020-11205
u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile in QSM8350, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155P, SA8195P,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile in QSM8350, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155P, SA8195P, SDX55M, SM8250, SM8350, SM8350P, SXR2130, SXR2130P
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.20% probability · 10th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190, CWE-787
- Affected
- qualcomm/qsm8350 firmware · qualcomm/sa6145p firmware · qualcomm/sa6150p firmware · qualcomm/sa6155 firmware · qualcomm/sa6155p firmware · qualcomm/sa8150p firmware · qualcomm/sa8155p firmware · qualcomm/sa8195p firmware · qualcomm/sdx55m firmware · qualcomm/sm8250 firmware · qualcomm/sm8350 firmware · qualcomm/sm8350p firmware · qualcomm/sxr2130 firmware · qualcomm/sxr2130p firmware
- Source
- product-security@qualcomm.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.