HIGH · 8.4

CVE-2020-11242

User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile

Vulnerability Description

User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile

CVSS Score

8.4

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
QualcommPm660 Firmware-
QualcommPm660-
QualcommPm660A Firmware-
QualcommPm660A-
QualcommPm660L Firmware-
QualcommPm660L-
QualcommPm855A Firmware-
QualcommPm855A-
QualcommPmm855Au Firmware-
QualcommPmm855Au-
QualcommQat3514 Firmware-
QualcommQat3514-
QualcommQat3522 Firmware-
QualcommQat3522-
QualcommQat3550 Firmware-
QualcommQat3550-
QualcommQca6564A Firmware-
QualcommQca6564A-
QualcommQca6564Au Firmware-
QualcommQca6564Au-

References

FAQ

What is CVE-2020-11242?

CVE-2020-11242 is a vulnerability with a CVSS score of 8.4 (HIGH). User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile

How severe is CVE-2020-11242?

CVE-2020-11242 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11242?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Pm660 Firmware, Qualcomm Pm660, Qualcomm Pm660A Firmware, Qualcomm Pm660A, Qualcomm Pm660L Firmware.