SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-11209

Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439

MEDIUM 5.5EPSS 1.57%

Does this matter?

Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.

Description

Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
1.57% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
qualcomm/sd820 firmware · qualcomm/sd821 firmware · qualcomm/qcs603 firmware · qualcomm/qcs605 firmware · qualcomm/sda855 firmware · qualcomm/sa6155p firmware · qualcomm/sa6145p firmware · qualcomm/sa6155 firmware · qualcomm/sd855 firmware · qualcomm/sd 675 firmware · qualcomm/sd660 firmware · qualcomm/sd429 firmware · qualcomm/sd439 firmware
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.