CVE-2020-11201
Last modified
CVE-2020-11201 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA845, SDM640, SDM830, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM8150, SM8150P. EPSS estimates a 1.80% chance of exploitation in the next 30 days.
Description
Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA845, SDM640, SDM830, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM8150, SM8150P
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Qcm6125 Firmware | All versions |
| Qualcomm | Qcs410 Firmware | All versions |
| Qualcomm | Qcs603 Firmware | All versions |
| Qualcomm | Qcs605 Firmware | All versions |
| Qualcomm | Qcs610 Firmware | All versions |
| Qualcomm | Qcs6125 Firmware | All versions |
| Qualcomm | Sa6145p Firmware | All versions |
| Qualcomm | Sa6155 Firmware | All versions |
| Qualcomm | Sa6155p Firmware | All versions |
| Qualcomm | Sa8155 Firmware | All versions |
| Qualcomm | Sa8155p Firmware | All versions |
| Qualcomm | Sda640 Firmware | All versions |
| Qualcomm | Sda845 Firmware | All versions |
| Qualcomm | Sdm640 Firmware | All versions |
| Qualcomm | Sdm830 Firmware | All versions |
| Qualcomm | Sdm845 Firmware | All versions |
| Qualcomm | Sdx50m Firmware | All versions |
| Qualcomm | Sdx55 Firmware | All versions |
| Qualcomm | Sdx55m Firmware | All versions |
| Qualcomm | Sm6125 Firmware | All versions |
| Qualcomm | Sm6150 Firmware | All versions |
| Qualcomm | Sm6250 Firmware | All versions |
| Qualcomm | Sm6250p Firmware | All versions |
| Qualcomm | Sm7125 Firmware | All versions |
| Qualcomm | Sm7150 Firmware | All versions |
| Qualcomm | Sm7150p Firmware | All versions |
| Qualcomm | Sm8150 Firmware | All versions |
| Qualcomm | Sm8150p Firmware | All versions |
References
- https://blog.checkpoint.com/2020/08/06/achilles-small-chip-big-peril/Third Party Advisory
- https://research.checkpoint.com/2021/pwn2own-qualcomm-dsp/Exploit, Third Party Advisory
- https://www.qualcomm.com/company/product-security/bulletins/november-2020-bulletinBroken Link, Vendor Advisory
- https://blog.checkpoint.com/2020/08/06/achilles-small-chip-big-peril/Third Party Advisory
- https://research.checkpoint.com/2021/pwn2own-qualcomm-dsp/Exploit, Third Party Advisory
- https://www.qualcomm.com/company/product-security/bulletins/november-2020-bulletinBroken Link, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11201?
How severe is CVE-2020-11201?
How do I fix CVE-2020-11201?
Are you affected by CVE-2020-11201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
