First published: Thu Nov 12 2020(Updated: )
Out of Bound issue in DSP services while processing received arguments due to improper validation of length received as an argument' in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm SD 820 Firmware | ||
Qualcomm Snapdragon 820 | ||
Qualcomm SD821 Firmware | ||
Qualcomm SD821 Firmware | ||
Qualcomm QCS603 | ||
Qualcomm QCS603 Firmware | ||
Qualcomm QCS605 | ||
Qualcomm QCS605 Firmware | ||
Qualcomm SDA855 Firmware | ||
Qualcomm SDA855 Firmware | ||
Qualcomm SA6155 | ||
Qualcomm SA6155P | ||
Qualcomm SA6145P Firmware | ||
Qualcomm SA6145P Firmware | ||
Qualcomm SA6155 | ||
Qualcomm SA6155 Firmware | ||
Qualcomm Snapdragon 855 | ||
Qualcomm Snapdragon 855 | ||
Qualcomm SD 675 Firmware | ||
Qualcomm Snapdragon 675 | ||
Qualcomm Snapdragon 660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SD429 | ||
Qualcomm SD429 Firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm Snapdragon 439 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11208 has been classified as a critical severity vulnerability due to the potential for exploitation via out-of-bounds memory access.
To fix CVE-2020-11208, update your Qualcomm firmware to the latest version that addresses this vulnerability.
CVE-2020-11208 affects several Qualcomm devices including SD820, SD821, QCS603, and others listed in the vulnerability report.
CVE-2020-11208 is an out-of-bounds vulnerability that arises from improper validation of argument lengths in DSP services.
The potential impacts of CVE-2020-11208 include unauthorized access to sensitive data and the possibility of executing arbitrary code on the affected device.