Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-11169


u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8053, QCA6390, QCN7605, QCN7606, SA415M, SA515M, SA6155P, SA8155P, SC8180X, SDX55


Published

2020-11-02T07:15:13.997

Last Modified

2024-11-21T04:57:01.080

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-125
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm apq8009_firmware - Yes
Hardware qualcomm apq8009 - No
Operating System qualcomm apq8053_firmware - Yes
Hardware qualcomm apq8053 - No
Operating System qualcomm qca6390_firmware - Yes
Hardware qualcomm qca6390 - No
Operating System qualcomm qcn7605_firmware - Yes
Hardware qualcomm qcn7605 - No
Operating System qualcomm qcn7606_firmware - Yes
Hardware qualcomm qcn7606 - No
Operating System qualcomm sa415m_firmware - Yes
Hardware qualcomm sa415m - No
Operating System qualcomm sa515m_firmware - Yes
Hardware qualcomm sa515m - No
Operating System qualcomm sa6155p_firmware - Yes
Hardware qualcomm sa6155p - No
Operating System qualcomm sa8155p_firmware - Yes
Hardware qualcomm sa8155p - No
Operating System qualcomm sc8180x_firmware - Yes
Hardware qualcomm sc8180x - No
Operating System qualcomm sdx55_firmware - Yes
Hardware qualcomm sdx55 - No

References