SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11205

u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile in QSM8350, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155P, SA8195P,…

HIGH 7.8EPSS 0.20%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile in QSM8350, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155P, SA8195P, SDX55M, SM8250, SM8350, SM8350P, SXR2130, SXR2130P

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.20% probability · 10th percentile
CISA KEV
Not listed
Weakness
CWE-190, CWE-787
Affected
qualcomm/qsm8350 firmware · qualcomm/sa6145p firmware · qualcomm/sa6150p firmware · qualcomm/sa6155 firmware · qualcomm/sa6155p firmware · qualcomm/sa8150p firmware · qualcomm/sa8155p firmware · qualcomm/sa8195p firmware · qualcomm/sdx55m firmware · qualcomm/sm8250 firmware · qualcomm/sm8350 firmware · qualcomm/sm8350p firmware · qualcomm/sxr2130 firmware · qualcomm/sxr2130p firmware
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.