Vulnerability Description
Out of bound memory access while processing frames due to lack of check of invalid frames received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Apq8017 | - |
| Qualcomm | Apq8037 | All versions |
| Qualcomm | Apq8052 | All versions |
| Qualcomm | Apq8053 | All versions |
| Qualcomm | Apq8056 | All versions |
| Qualcomm | Apq8064Au | All versions |
| Qualcomm | Apq8076 | All versions |
| Qualcomm | Apq8096Au | All versions |
| Qualcomm | Aqt1000 | All versions |
| Qualcomm | Ar8031 | All versions |
| Qualcomm | Ar8035 | All versions |
| Qualcomm | Csra6620 | All versions |
| Qualcomm | Csra6640 | All versions |
| Qualcomm | Mdm9640 | All versions |
| Qualcomm | Mdm9650 | All versions |
| Qualcomm | Msm8917 | All versions |
| Qualcomm | Msm8920 | All versions |
| Qualcomm | Msm8937 | All versions |
| Qualcomm | Msm8940 | All versions |
| Qualcomm | Msm8952 | All versions |
Related Weaknesses (CWE)
References
- https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletBroken Link
- https://www.qualcomm.com/company/product-security/bulletins/december-2020-securiVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletBroken Link
FAQ
What is CVE-2020-11139?
CVE-2020-11139 is a vulnerability with a CVSS score of 7.5 (HIGH). Out of bound memory access while processing frames due to lack of check of invalid frames received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon ...
How severe is CVE-2020-11139?
CVE-2020-11139 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11139?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Apq8017, Qualcomm Apq8037, Qualcomm Apq8052, Qualcomm Apq8053, Qualcomm Apq8056.