CVE-2020-11116: Critical severity Google Android vulnerability
u'Possible out of bound write while processing association response received from host due to lack of check of IE length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, APQ8098, Bitra, Kamorta, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCM2150, QCN7605, QCS405, QCS605, QCS610, QM215, SA6155P, Saipan, SC8180X, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11116?
CVE-2020-11116 has a high severity rating due to a possible out of bounds write vulnerability that could be exploited.
How do I fix CVE-2020-11116?
To fix CVE-2020-11116, apply the latest firmware updates provided by Qualcomm for affected devices.
What types of devices are affected by CVE-2020-11116?
CVE-2020-11116 affects various Qualcomm Snapdragon products including automotive and mobile devices.
Is CVE-2020-11116 a remote code execution vulnerability?
CVE-2020-11116 can lead to remote code execution if exploited through malicious association responses.
Can CVE-2020-11116 be exploited without user interaction?
Yes, CVE-2020-11116 may be exploited without user interaction, making it a significant security concern.