HIGH · 7.5

CVE-2020-11157

u'Lack of handling unexpected control messages while encryption was in progress can terminate the connection and thus leading to a DoS' in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer...

Vulnerability Description

u'Lack of handling unexpected control messages while encryption was in progress can terminate the connection and thus leading to a DoS' in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8076, MDM9640, MDM9650, MSM8905, MSM8917, MSM8937, MSM8940, MSM8953, QCA6174A, QCA9886, QCM2150, QM215, SDM429, SDM439, SDM450, SDM632

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
QualcommApq8053 Firmware-
QualcommApq8053-
QualcommApq8076 Firmware-
QualcommApq8076-
QualcommMdm9640 Firmware-
QualcommMdm9640-
QualcommMdm9650 Firmware-
QualcommMdm9650-
QualcommMsm8905 Firmware-
QualcommMsm8905-
QualcommMsm8917 Firmware-
QualcommMsm8917-
QualcommMsm8937 Firmware-
QualcommMsm8937-
QualcommMsm8940 Firmware-
QualcommMsm8940-
QualcommMsm8953 Firmware-
QualcommMsm8953-
QualcommQca6174A Firmware-
QualcommQca6174A-

References

FAQ

What is CVE-2020-11157?

CVE-2020-11157 is a vulnerability with a CVSS score of 7.5 (HIGH). u'Lack of handling unexpected control messages while encryption was in progress can terminate the connection and thus leading to a DoS' in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer...

How severe is CVE-2020-11157?

CVE-2020-11157 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11157?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Apq8053 Firmware, Qualcomm Apq8053, Qualcomm Apq8076 Firmware, Qualcomm Apq8076, Qualcomm Mdm9640 Firmware.