CVE-2020-11261
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-787, CWE-20
מוצרים מושפעים
qualcomm: apq8009 firmware; qualcomm: apq8009; qualcomm: apq8009w firmware; qualcomm: apq8009w; qualcomm: apq8017 firmware; qualcomm: apq8017; qualcomm: apq8037 firmware; qualcomm: apq8037; qualcomm: apq8053 firmware; qualcomm: apq8053; qualcomm: apq8064au firmware; qualcomm: apq8064au; qualcomm: apq8096au firmware; qualcomm: apq8096au; qualcomm: aqt1000 firmware
קישורים
- https://www.qualcomm.com/company/product-security/bulletins/january-2021-bulle… PatchVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/january-2021-bulle… PatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource