HIGH · 8.4

CVE-2020-11236

Memory corruption due to invalid value of total dimension in the non-histogram type KPI could lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mo...

Vulnerability Description

Memory corruption due to invalid value of total dimension in the non-histogram type KPI could lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

CVSS Score

8.4

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QualcommCsrb31024 Firmware-
QualcommCsrb31024-
QualcommPm3003A Firmware-
QualcommPm3003A-
QualcommPm6150A Firmware-
QualcommPm6150A-
QualcommPm6150L Firmware-
QualcommPm6150L-
QualcommPm6350 Firmware-
QualcommPm6350-
QualcommPm7150A Firmware-
QualcommPm7150A-
QualcommPm7150L Firmware-
QualcommPm7150L-
QualcommPm7250 Firmware-
QualcommPm7250-
QualcommPm7250B Firmware-
QualcommPm7250B-
QualcommPm8008 Firmware-
QualcommPm8008-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11236?

CVE-2020-11236 is a vulnerability with a CVSS score of 8.4 (HIGH). Memory corruption due to invalid value of total dimension in the non-histogram type KPI could lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mo...

How severe is CVE-2020-11236?

CVE-2020-11236 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11236?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Csrb31024 Firmware, Qualcomm Csrb31024, Qualcomm Pm3003A Firmware, Qualcomm Pm3003A, Qualcomm Pm6150A Firmware.