Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-11181


Out of bound access issue while handling cvp process control command due to improper validation of buffer pointer received from HLOS in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.8, requiring local system access to exploit with relatively low complexity without requiring user interaction requiring only low-level privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 78 products from qualcomm, from qualcomm, from qualcomm and 75 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2021, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2021-01-21T10:15:14.197

Last Modified

2024-11-21T04:57:07.390

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm pm3003a_firmware - Yes
Hardware qualcomm pm3003a - No
Operating System qualcomm pm8009_firmware - Yes
Hardware qualcomm pm8009 - No
Operating System qualcomm pm8150a_firmware - Yes
Hardware qualcomm pm8150a - No
Operating System qualcomm pm8150b_firmware - Yes
Hardware qualcomm pm8150b - No
Operating System qualcomm pm8150c_firmware - Yes
Hardware qualcomm pm8150c - No
Operating System qualcomm pm8150l_firmware - Yes
Hardware qualcomm pm8150l - No
Operating System qualcomm pm8250_firmware - Yes
Hardware qualcomm pm8250 - No
Operating System qualcomm pmk8002_firmware - Yes
Hardware qualcomm pmk8002 - No
Operating System qualcomm pmr525_firmware - Yes
Hardware qualcomm pmr525 - No
Operating System qualcomm pmx55_firmware - Yes
Hardware qualcomm pmx55 - No
Operating System qualcomm qbt2000_firmware - Yes
Hardware qualcomm qbt2000 - No
Operating System qualcomm qca6390_firmware - Yes
Hardware qualcomm qca6390 - No
Operating System qualcomm qca6391_firmware - Yes
Hardware qualcomm qca6391 - No
Operating System qualcomm qca6421_firmware - Yes
Hardware qualcomm qca6421 - No
Operating System qualcomm qca6426_firmware - Yes
Hardware qualcomm qca6426 - No
Operating System qualcomm qca6431_firmware - Yes
Hardware qualcomm qca6431 - No
Operating System qualcomm qca6436_firmware - Yes
Hardware qualcomm qca6436 - No
Operating System qualcomm qfs2530_firmware - Yes
Hardware qualcomm qfs2530 - No
Operating System qualcomm qfs2580_firmware - Yes
Hardware qualcomm qfs2580 - No
Operating System qualcomm qsm8250_firmware - Yes
Hardware qualcomm qsm8250 - No
Operating System qualcomm qtc800h_firmware - Yes
Hardware qualcomm qtc800h - No
Operating System qualcomm qtc801s_firmware - Yes
Hardware qualcomm qtc801s - No
Operating System qualcomm sd865_5g_firmware - Yes
Hardware qualcomm sd865_5g - No
Operating System qualcomm sdr8250_firmware - Yes
Hardware qualcomm sdr8250 - No
Operating System qualcomm sdr865_firmware - Yes
Hardware qualcomm sdr865 - No
Operating System qualcomm sdx55_firmware - Yes
Hardware qualcomm sdx55 - No
Operating System qualcomm sdx55m_firmware - Yes
Hardware qualcomm sdx55m - No
Operating System qualcomm sdxr2_5g_firmware - Yes
Hardware qualcomm sdxr2_5g - No
Operating System qualcomm smb1355_firmware - Yes
Hardware qualcomm smb1355 - No
Operating System qualcomm smb1390_firmware - Yes
Hardware qualcomm smb1390 - No
Operating System qualcomm smr525_firmware - Yes
Hardware qualcomm smr525 - No
Operating System qualcomm smr526_firmware - Yes
Hardware qualcomm smr526 - No
Operating System qualcomm wcd9380_firmware - Yes
Hardware qualcomm wcd9380 - No
Operating System qualcomm wcd9385_firmware - Yes
Hardware qualcomm wcd9385 - No
Operating System qualcomm wcn6750_firmware - Yes
Hardware qualcomm wcn6750 - No
Operating System qualcomm wcn6850_firmware - Yes
Hardware qualcomm wcn6850 - No
Operating System qualcomm wcn6851_firmware - Yes
Hardware qualcomm wcn6851 - No
Operating System qualcomm wsa8810_firmware - Yes
Hardware qualcomm wsa8810 - No
Operating System qualcomm wsa8815_firmware - Yes
Hardware qualcomm wsa8815 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For qualcomm's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.