Vulnerability Description
Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Ar7420 Firmware | - |
| Qualcomm | Ar7420 | - |
| Qualcomm | Ar9580 Firmware | - |
| Qualcomm | Ar9580 | - |
| Qualcomm | Csr8811 Firmware | - |
| Qualcomm | Csr8811 | - |
| Qualcomm | Ipq4018 Firmware | - |
| Qualcomm | Ipq4018 | - |
| Qualcomm | Ipq4019 Firmware | - |
| Qualcomm | Ipq4019 | - |
| Qualcomm | Ipq4028 Firmware | - |
| Qualcomm | Ipq4028 | - |
| Qualcomm | Ipq4029 Firmware | - |
| Qualcomm | Ipq4029 | - |
| Qualcomm | Qca10901 Firmware | - |
| Qualcomm | Qca10901 | - |
| Qualcomm | Qca4024 Firmware | - |
| Qualcomm | Qca4024 | - |
| Qualcomm | Qca7500 Firmware | - |
| Qualcomm | Qca7500 | - |
Related Weaknesses (CWE)
References
- https://www.qualcomm.com/company/product-security/bulletins/january-2021-bulletiVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/january-2021-bulletiVendor Advisory
FAQ
What is CVE-2020-11265?
CVE-2020-11265 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking
How severe is CVE-2020-11265?
CVE-2020-11265 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11265?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Ar7420 Firmware, Qualcomm Ar7420, Qualcomm Ar9580 Firmware, Qualcomm Ar9580, Qualcomm Csr8811 Firmware.