// For flags

CVE-2020-11153

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to remote code execution' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8053, QCA6390, QCA9379, QCN7605, SC8180X, SDX55

Un acceso a la memoria fuera de límite mientras se procesan unos datos GATT recibidos debido a una falta de comprobación de la longitud de los datos pdu y que conlleva a una ejecución de código remota en los productos Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile en versiones APQ8053, QCA6390, QCA9379, QCN7605, SC8180X, SDX55

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-03-31 CVE Reserved
  • 2020-11-02 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Qualcomm
Search vendor "Qualcomm"
Apq8053 Firmware
Search vendor "Qualcomm" for product "Apq8053 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Apq8053
Search vendor "Qualcomm" for product "Apq8053"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Qca6390 Firmware
Search vendor "Qualcomm" for product "Qca6390 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Qca6390
Search vendor "Qualcomm" for product "Qca6390"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Qca9379 Firmware
Search vendor "Qualcomm" for product "Qca9379 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Qca9379
Search vendor "Qualcomm" for product "Qca9379"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Qcn7605 Firmware
Search vendor "Qualcomm" for product "Qcn7605 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Qcn7605
Search vendor "Qualcomm" for product "Qcn7605"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sc8180x Firmware
Search vendor "Qualcomm" for product "Sc8180x Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sc8180x
Search vendor "Qualcomm" for product "Sc8180x"
--
Safe
Qualcomm
Search vendor "Qualcomm"
Sdx55 Firmware
Search vendor "Qualcomm" for product "Sdx55 Firmware"
--
Affected
in Qualcomm
Search vendor "Qualcomm"
Sdx55
Search vendor "Qualcomm" for product "Sdx55"
--
Safe