CVE-2020-11145

HIGHCVSS 7.5/10EPSS 0.78%

Last modified

CVE-2020-11145 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Divide by zero issue can happen while updating delta extension header due to improper validation of master SN and extension header SN in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. EPSS estimates a 0.78% chance of exploitation in the next 30 days.

Description

Divide by zero issue can happen while updating delta extension header due to improper validation of master SN and extension header SN in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.78%

51.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
QualcommApq8009All versions
QualcommApq8009wAll versions
QualcommApq8017All versions
QualcommApq8037All versions
QualcommApq8053All versions
QualcommApq8084All versions
QualcommApq8096auAll versions
QualcommAqt1000All versions
QualcommAr6003All versions
QualcommAr8035All versions
QualcommAr8151All versions
QualcommCsr6030All versions
QualcommCsrb31024All versions
QualcommFsm10055All versions
QualcommMdm8207All versions
QualcommMdm8215All versions
QualcommMdm8215mAll versions
QualcommMdm8615mAll versions
QualcommMdm9150All versions
QualcommMdm9205All versions
QualcommMdm9206All versions
QualcommMdm9207All versions
QualcommMdm9215All versions
QualcommMdm9230All versions
QualcommMdm9250All versions
QualcommMdm9310All versions
QualcommMdm9330All versions
QualcommMdm9607All versions
QualcommMdm9615All versions
QualcommMdm9615mAll versions
QualcommMdm9625All versions
QualcommMdm9628All versions
QualcommMdm9630All versions
QualcommMdm9635mAll versions
QualcommMdm9640All versions
QualcommMdm9645All versions
QualcommMdm9650All versions
QualcommMdm9655All versions
QualcommMsm8108All versions
QualcommMsm8208All versions
QualcommMsm8209All versions
QualcommMsm8608All versions
QualcommMsm8909wAll versions
QualcommMsm8917All versions
QualcommMsm8920All versions
QualcommMsm8937All versions
QualcommMsm8940All versions
QualcommMsm8953All versions
QualcommMsm8976All versions
QualcommMsm8976sgAll versions

Showing 50 of 413 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-11145?
Divide by zero issue can happen while updating delta extension header due to improper validation of master SN and extension header SN in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
How severe is CVE-2020-11145?
CVE-2020-11145 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.78% probability of exploitation in the next 30 days.
How do I fix CVE-2020-11145?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-11145?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST