Vulnerability Description
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Ipq4019 Firmware | - |
| Qualcomm | Ipq4019 | - |
| Qualcomm | Ipq6018 Firmware | - |
| Qualcomm | Ipq6018 | - |
| Qualcomm | Ipq8064 Firmware | - |
| Qualcomm | Ipq8064 | - |
| Qualcomm | Ipq8074 Firmware | - |
| Qualcomm | Ipq8074 | - |
| Qualcomm | Qca4531 Firmware | - |
| Qualcomm | Qca4531 | - |
| Qualcomm | Qca9531 Firmware | - |
| Qualcomm | Qca9531 | - |
| Qualcomm | Qca9980 Firmware | - |
| Qualcomm | Qca9980 | - |
Related Weaknesses (CWE)
References
- https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletinBroken Link
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1065ExploitThird Party Advisory
- https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletinBroken Link
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1065ExploitThird Party Advisory
FAQ
What is CVE-2020-11117?
CVE-2020-11117 is a vulnerability with a CVSS score of 9.8 (CRITICAL). u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, ...
How severe is CVE-2020-11117?
CVE-2020-11117 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-11117?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Ipq4019 Firmware, Qualcomm Ipq4019, Qualcomm Ipq6018 Firmware, Qualcomm Ipq6018, Qualcomm Ipq8064 Firmware.