CVE-2020-11163
Last modified
CVE-2020-11163 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters received from the ePDG server in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile. EPSS estimates a 0.82% chance of exploitation in the next 30 days.
Description
Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters received from the ePDG server in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Apq8017 Firmware | All versions |
| Qualcomm | Aqt1000 Firmware | All versions |
| Qualcomm | Ar8035 Firmware | All versions |
| Qualcomm | Csrb31024 Firmware | All versions |
| Qualcomm | Msm8917 Firmware | All versions |
| Qualcomm | Pm215 Firmware | All versions |
| Qualcomm | Pm3003a Firmware | All versions |
| Qualcomm | Pm4125 Firmware | All versions |
| Qualcomm | Pm4250 Firmware | All versions |
| Qualcomm | Pm439 Firmware | All versions |
| Qualcomm | Pm456 Firmware | All versions |
| Qualcomm | Pm6125 Firmware | All versions |
| Qualcomm | Pm6150 Firmware | All versions |
| Qualcomm | Pm6150a Firmware | All versions |
| Qualcomm | Pm6150l Firmware | All versions |
| Qualcomm | Pm6250 Firmware | All versions |
| Qualcomm | Pm640a Firmware | All versions |
| Qualcomm | Pm640l Firmware | All versions |
| Qualcomm | Pm640p Firmware | All versions |
| Qualcomm | Pm7150a Firmware | All versions |
| Qualcomm | Pm7150l Firmware | All versions |
| Qualcomm | Pm7250 Firmware | All versions |
| Qualcomm | Pm7250b Firmware | All versions |
| Qualcomm | Pm8004 Firmware | All versions |
| Qualcomm | Pm8008 Firmware | All versions |
| Qualcomm | Pm8009 Firmware | All versions |
| Qualcomm | Pm8150 Firmware | All versions |
| Qualcomm | Pm8150a Firmware | All versions |
| Qualcomm | Pm8150b Firmware | All versions |
| Qualcomm | Pm8150c Firmware | All versions |
| Qualcomm | Pm8150l Firmware | All versions |
| Qualcomm | Pm8250 Firmware | All versions |
| Qualcomm | Pm855 Firmware | All versions |
| Qualcomm | Pm855a Firmware | All versions |
| Qualcomm | Pm855b Firmware | All versions |
| Qualcomm | Pm855l Firmware | All versions |
| Qualcomm | Pm855p Firmware | All versions |
| Qualcomm | Pm8909 Firmware | All versions |
| Qualcomm | Pm8916 Firmware | All versions |
| Qualcomm | Pm8937 Firmware | All versions |
| Qualcomm | Pmc1000h Firmware | All versions |
| Qualcomm | Pmi632 Firmware | All versions |
| Qualcomm | Pmi8937 Firmware | All versions |
| Qualcomm | Pmi8952 Firmware | All versions |
| Qualcomm | Pmk8002 Firmware | All versions |
| Qualcomm | Pmm855au Firmware | All versions |
| Qualcomm | Pmr525 Firmware | All versions |
| Qualcomm | Pmr735a Firmware | All versions |
| Qualcomm | Pmx24 Firmware | All versions |
| Qualcomm | Pmx50 Firmware | All versions |
Showing 50 of 250 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11163?
How severe is CVE-2020-11163?
How do I fix CVE-2020-11163?
Are you affected by CVE-2020-11163?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
