CVE-2020-11242: High severity Google Android vulnerability

Published Apr 5, 2021
·
Updated

User could gain access to secure memory due to incorrect argument into address range validation api used in SDI to capture requested contents in Snapdragon Industrial IOT, Snapdragon Mobile

Affected Software

77 affected components
Google Android
Qualcomm Pm660 Firmware
Qualcomm Pm660
Qualcomm Pm660a Firmware
Qualcomm Pm660a
Qualcomm Pm660l Firmware
Qualcomm Pm660l
Qualcomm Pm855a Firmware
Qualcomm Pm855a
Qualcomm Pmm855au Firmware
Qualcomm Pmm855au
Qualcomm Qat3514 Firmware
Qualcomm Qat3514
Qualcomm Qat3522 Firmware
Qualcomm Qat3522
Qualcomm Qat3550 Firmware
Qualcomm Qat3550
Qualcomm Qca6564a Firmware
Qualcomm Qca6564a
Qualcomm Qca6564au Firmware
Qualcomm Qca6564au
Qualcomm Qca6574a Firmware
Qualcomm Qca6574a
Qualcomm Qca6574au Firmware
Qualcomm QCA6574AU
Qualcomm Qca6595 Firmware
Qualcomm Qca6595
Qualcomm Qca6595au Firmware
Qualcomm Qca6595au
Qualcomm Qet4100 Firmware
Qualcomm Qet4100
Qualcomm Qet4101 Firmware
Qualcomm Qet4101
Qualcomm Qet4200aq Firmware
Qualcomm Qet4200aq
Qualcomm Qln1021aq Firmware
Qualcomm Qln1021aq
Qualcomm Qln1031 Firmware
Qualcomm Qln1031
Qualcomm Qln1036aq Firmware
Qualcomm Qln1036aq
Qualcomm Qpa4340 Firmware
Qualcomm Qpa4340
Qualcomm Qpa4360 Firmware
Qualcomm Qpa4360
Qualcomm Qpa5460 Firmware
Qualcomm Qpa5460
Qualcomm Qtc800h Firmware
Qualcomm Qtc800h
Qualcomm Qtc800s Firmware
Qualcomm Qtc800s
Qualcomm Rsw8577 Firmware
Qualcomm Rsw8577
Qualcomm Sd455 Firmware
Qualcomm Sd455
Qualcomm Sd636 Firmware
Qualcomm Sd636
Qualcomm Sd660 Firmware
Qualcomm Sd660
Qualcomm Sdm630 Firmware
Qualcomm SDM630
Qualcomm Sdr660 Firmware
Qualcomm Sdr660
Qualcomm Smb1351 Firmware
Qualcomm Smb1351
Qualcomm Wcd9335 Firmware
Qualcomm Wcd9335
Qualcomm Wcd9340 Firmware
Qualcomm Wcd9340
Qualcomm Wcd9341 Firmware
Qualcomm Wcd9341
Qualcomm Wcn3950 Firmware
Qualcomm Wcn3950
Qualcomm Wcn3980 Firmware
Qualcomm Wcn3980
Qualcomm Wcn3990 Firmware
Qualcomm Wcn3990

Event History

Apr 5, 2021
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Apr 7, 2021
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-11242?

The severity of CVE-2020-11242 is high with a severity value of 7.8.

2

What software is affected by CVE-2020-11242?

Google Android and various Qualcomm firmware versions are affected by CVE-2020-11242.

3

How can an attacker gain access to secure memory in CVE-2020-11242?

An attacker can gain access to secure memory in CVE-2020-11242 by using incorrect arguments in the address range validation API.

4

What is the official reference for CVE-2020-11242?

The official references for CVE-2020-11242 are: Qualcomm Product Security Bulletin (April 2021), Google Android Security Bulletin (April 2021).

5

Where can I find more information about CVE-2020-11242?

You can find more information about CVE-2020-11242 in the Qualcomm Product Security Bulletin (April 2021) and the Google Android Security Bulletin (April 2021).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203