Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-11153


u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to remote code execution' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8053, QCA6390, QCA9379, QCN7605, SC8180X, SDX55


Published

2020-11-02T07:15:13.530

Last Modified

2024-11-21T04:56:56.977

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm apq8053_firmware - Yes
Hardware qualcomm apq8053 - No
Operating System qualcomm qca6390_firmware - Yes
Hardware qualcomm qca6390 - No
Operating System qualcomm qca9379_firmware - Yes
Hardware qualcomm qca9379 - No
Operating System qualcomm qcn7605_firmware - Yes
Hardware qualcomm qcn7605 - No
Operating System qualcomm sc8180x_firmware - Yes
Hardware qualcomm sc8180x - No
Operating System qualcomm sdx55_firmware - Yes
Hardware qualcomm sdx55 - No

References