MEDIUM · 6.7

CVE-2020-11183

A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code as that service in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consume...

Vulnerability Description

A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code as that service in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QualcommApq8009-
QualcommApq8009W-
QualcommApq8017-
QualcommApq8037-
QualcommApq8053-
QualcommApq8096Au-
QualcommAr8151-
QualcommMdm9206-
QualcommMdm9250-
QualcommMdm9650-
QualcommMdm9655-
QualcommMsm8909W-
QualcommMsm8917-
QualcommMsm8920-
QualcommMsm8937-
QualcommMsm8940-
QualcommMsm8953-
QualcommMsm8996Au-
QualcommPm215-
QualcommPm439-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11183?

CVE-2020-11183 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code as that service in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consume...

How severe is CVE-2020-11183?

CVE-2020-11183 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11183?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Apq8009, Qualcomm Apq8009W, Qualcomm Apq8017, Qualcomm Apq8037, Qualcomm Apq8053.