Vulnerability Description
u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile in QSM8350, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155P, SA8195P, SDX55M, SM8250, SM8350, SM8350P, SXR2130, SXR2130P
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Qsm8350 Firmware | - |
| Qualcomm | Qsm8350 | - |
| Qualcomm | Sa6145P Firmware | - |
| Qualcomm | Sa6145P | - |
| Qualcomm | Sa6150P Firmware | - |
| Qualcomm | Sa6150P | - |
| Qualcomm | Sa6155 Firmware | - |
| Qualcomm | Sa6155 | - |
| Qualcomm | Sa6155P Firmware | - |
| Qualcomm | Sa6155P | - |
| Qualcomm | Sa8150P Firmware | - |
| Qualcomm | Sa8150P | - |
| Qualcomm | Sa8155P Firmware | - |
| Qualcomm | Sa8155P | - |
| Qualcomm | Sa8195P Firmware | - |
| Qualcomm | Sa8195P | - |
| Qualcomm | Sdx55M Firmware | - |
| Qualcomm | Sdx55M | - |
| Qualcomm | Sm8250 Firmware | - |
| Qualcomm | Sm8250 | - |
Related Weaknesses (CWE)
References
- https://www.qualcomm.com/company/product-security/bulletins/november-2020-bulletVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/november-2020-bulletVendor Advisory
FAQ
What is CVE-2020-11205?
CVE-2020-11205 is a vulnerability with a CVSS score of 7.8 (HIGH). u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile in QSM8350, SA6145P, SA6...
How severe is CVE-2020-11205?
CVE-2020-11205 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11205?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Qsm8350 Firmware, Qualcomm Qsm8350, Qualcomm Sa6145P Firmware, Qualcomm Sa6145P, Qualcomm Sa6150P Firmware.