CVE-2020-11242
HIGHCVSS 7.8/10EPSS 0.20%
Last modified
CVE-2020-11242 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Pm660 Firmware | All versions |
| Qualcomm | Pm660a Firmware | All versions |
| Qualcomm | Pm660l Firmware | All versions |
| Qualcomm | Pm855a Firmware | All versions |
| Qualcomm | Pmm855au Firmware | All versions |
| Qualcomm | Qat3514 Firmware | All versions |
| Qualcomm | Qat3522 Firmware | All versions |
| Qualcomm | Qat3550 Firmware | All versions |
| Qualcomm | Qca6564a Firmware | All versions |
| Qualcomm | Qca6564au Firmware | All versions |
| Qualcomm | Qca6574a Firmware | All versions |
| Qualcomm | Qca6574au Firmware | All versions |
| Qualcomm | Qca6595 Firmware | All versions |
| Qualcomm | Qca6595au Firmware | All versions |
| Qualcomm | Qet4100 Firmware | All versions |
| Qualcomm | Qet4101 Firmware | All versions |
| Qualcomm | Qet4200aq Firmware | All versions |
| Qualcomm | Qln1021aq Firmware | All versions |
| Qualcomm | Qln1031 Firmware | All versions |
| Qualcomm | Qln1036aq Firmware | All versions |
| Qualcomm | Qpa4340 Firmware | All versions |
| Qualcomm | Qpa4360 Firmware | All versions |
| Qualcomm | Qpa5460 Firmware | All versions |
| Qualcomm | Qtc800h Firmware | All versions |
| Qualcomm | Qtc800s Firmware | All versions |
| Qualcomm | Rsw8577 Firmware | All versions |
| Qualcomm | Sd455 Firmware | All versions |
| Qualcomm | Sd636 Firmware | All versions |
| Qualcomm | Sd660 Firmware | All versions |
| Qualcomm | Sdm630 Firmware | All versions |
| Qualcomm | Sdr660 Firmware | All versions |
| Qualcomm | Smb1351 Firmware | All versions |
| Qualcomm | Wcd9335 Firmware | All versions |
| Qualcomm | Wcd9340 Firmware | All versions |
| Qualcomm | Wcd9341 Firmware | All versions |
| Qualcomm | Wcn3950 Firmware | All versions |
| Qualcomm | Wcn3980 Firmware | All versions |
| Qualcomm | Wcn3990 Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11242?
User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile
How severe is CVE-2020-11242?
CVE-2020-11242 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2020-11242?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-11237Memory crash when accessing histogram type KPI input receive…7.8
- CVE-2020-11238Possible Buffer over-read in ARP/NS parsing due to lack of c…7.5
- CVE-2020-11239Use after free issue when importing a DMA buffer by using th…7.8
- CVE-2020-1124An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-11240Memory corruption due to ioctl command size was incorrectly …7.8
- CVE-2020-11241Out of bound read will happen if EAPOL Key length is less th…7.5
- CVE-2020-11243RRC sends a connection establishment success to NAS even tho…7.5
- CVE-2020-11245Unintended reads and writes by NS EL2 in access control driv…7.8
- CVE-2020-11246A double free condition can occur when the device moves to s…7.8
- CVE-2020-11247Out of bound memory read while unpacking data due to lack of…9.1
- CVE-2020-1125An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-11250Use after free due to race condition when reopening the devi…7
Are you affected by CVE-2020-11242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
