CVE-2020-11264: Critical severity Google Android vulnerability
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11264?
The severity of CVE-2020-11264 is rated as high due to potential arbitrary network packet injection.
How do I fix CVE-2020-11264?
To fix CVE-2020-11264, you should update to the latest firmware version released by Qualcomm that addresses this vulnerability.
Which devices are affected by CVE-2020-11264?
CVE-2020-11264 affects multiple Qualcomm chipsets, including those used in Snapdragon Auto and Snapdragon Compute devices.
What type of vulnerability is CVE-2020-11264?
CVE-2020-11264 is an improper authentication vulnerability that can be exploited during the four-way handshake process.
What could an attacker achieve by exploiting CVE-2020-11264?
An attacker could inject arbitrary network packets, potentially compromising the integrity and availability of network communications.