HIGH · 7.5

CVE-2020-11268

Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile

Vulnerability Description

Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
QualcommApq8009-
QualcommApq8016-
QualcommApq8074-
QualcommApq8084-
QualcommApq8094-
QualcommAr6003-
QualcommMdm8215-
QualcommMdm8215M-
QualcommMdm8615M-
QualcommMdm9215-
QualcommMdm9235M-
QualcommMdm9310-
QualcommMdm9609-
QualcommMdm9615-
QualcommMdm9615M-
QualcommMdm9635M-
QualcommMdm9640-
QualcommMdm9645-
QualcommMsm8108-
QualcommMsm8208-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-11268?

CVE-2020-11268 is a vulnerability with a CVSS score of 7.5 (HIGH). Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile

How severe is CVE-2020-11268?

CVE-2020-11268 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-11268?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Apq8009, Qualcomm Apq8016, Qualcomm Apq8074, Qualcomm Apq8084, Qualcomm Apq8094.