CVE-2020-11201: Input Validation
Arbitrary access to DSP memory due to improper check in loaded library for data received from CPU side' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDA640, SDA845, SDM640, SDM830, SDM845, SDX50M, SDX55, SDX55M, SM6125, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM8150, SM8150P
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11201?
CVE-2020-11201 is a vulnerability that allows arbitrary access to DSP memory due to an improper check in a loaded library for data received from the CPU side.
Which software is affected by CVE-2020-11201?
The vulnerability affects Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in QCM6125, QCS410, QCS603, QCS605, QCS610, QCS6125, SA6145P, SA6155, SA6155P, SA8155, and other models listed in the official bulletin.
What is the severity of CVE-2020-11201?
CVE-2020-11201 has a severity level of 7.8 (high).
How can I fix CVE-2020-11201?
To fix CVE-2020-11201, users are advised to apply the necessary updates and patches provided by Qualcomm as mentioned in the official bulletin.
Where can I find more information about CVE-2020-11201?
More information about CVE-2020-11201 can be found in the official blog post and research report by Check Point, as well as the Qualcomm Product Security bulletins for November 2020.