CVE-2020-11242
HIGHCVSS 7.8/10EPSS 0.20%
Last modified
CVE-2020-11242 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Pm660 Firmware | All versions |
| Qualcomm | Pm660a Firmware | All versions |
| Qualcomm | Pm660l Firmware | All versions |
| Qualcomm | Pm855a Firmware | All versions |
| Qualcomm | Pmm855au Firmware | All versions |
| Qualcomm | Qat3514 Firmware | All versions |
| Qualcomm | Qat3522 Firmware | All versions |
| Qualcomm | Qat3550 Firmware | All versions |
| Qualcomm | Qca6564a Firmware | All versions |
| Qualcomm | Qca6564au Firmware | All versions |
| Qualcomm | Qca6574a Firmware | All versions |
| Qualcomm | Qca6574au Firmware | All versions |
| Qualcomm | Qca6595 Firmware | All versions |
| Qualcomm | Qca6595au Firmware | All versions |
| Qualcomm | Qet4100 Firmware | All versions |
| Qualcomm | Qet4101 Firmware | All versions |
| Qualcomm | Qet4200aq Firmware | All versions |
| Qualcomm | Qln1021aq Firmware | All versions |
| Qualcomm | Qln1031 Firmware | All versions |
| Qualcomm | Qln1036aq Firmware | All versions |
| Qualcomm | Qpa4340 Firmware | All versions |
| Qualcomm | Qpa4360 Firmware | All versions |
| Qualcomm | Qpa5460 Firmware | All versions |
| Qualcomm | Qtc800h Firmware | All versions |
| Qualcomm | Qtc800s Firmware | All versions |
| Qualcomm | Rsw8577 Firmware | All versions |
| Qualcomm | Sd455 Firmware | All versions |
| Qualcomm | Sd636 Firmware | All versions |
| Qualcomm | Sd660 Firmware | All versions |
| Qualcomm | Sdm630 Firmware | All versions |
| Qualcomm | Sdr660 Firmware | All versions |
| Qualcomm | Smb1351 Firmware | All versions |
| Qualcomm | Wcd9335 Firmware | All versions |
| Qualcomm | Wcd9340 Firmware | All versions |
| Qualcomm | Wcd9341 Firmware | All versions |
| Qualcomm | Wcn3950 Firmware | All versions |
| Qualcomm | Wcn3980 Firmware | All versions |
| Qualcomm | Wcn3990 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11242?
User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile
How severe is CVE-2020-11242?
CVE-2020-11242 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2020-11242?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2020-11242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
