CWE
119
Advisory Published
CVE Published
Updated

CVE-2020-11286: Buffer Overflow

First published: Mon Feb 01 2021(Updated: )

An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Credit: product-security@qualcomm.com

Affected SoftwareAffected VersionHow to fix
Android
Qualcomm APQ8009 Firmware
Qualcomm APQ8009
Qualcomm APQ8017
Qualcomm APQ8053 Firmware
Qualcomm APQ8064 AU Firmware
Qualcomm APQ8076 Firmware
Qualcomm APQ8096AU Firmware
Qualcomm AR8151 Firmware
Qualcomm CSR6030 Firmware
Qualcomm MDM9206 firmware
Qualcomm MDM9230 Firmware
Qualcomm MDM9250 Firmware
Qualcomm MDM9330 Firmware
Qualcomm MDM9607 firmware
Qualcomm MDM9626 Firmware
Qualcomm MDM9628
Qualcomm MDM9630 Firmware
Qualcomm MDM9640 Firmware
Qualcomm MDM9650 firmware
Qualcomm MDM9655 firmware
Qualcomm Snapdragon 8909
qualcomm MSM8937 firmware
Qualcomm MSM8996AU Firmware
Qualcomm pm660 firmware
Qualcomm pm660a firmware
Qualcomm PM660L Firmware
Qualcomm PM8004 Firmware
Qualcomm PM8005 Firmware
Qualcomm Snapdragon 8909
Qualcomm PM8916 Firmware
Qualcomm MSM8937
Qualcomm PMI8952 Firmware
Qualcomm PM8953 Firmware
Qualcomm 8956
Qualcomm pmi8996 firmware
Qualcomm 8998
Qualcomm PMD9607 Firmware
Qualcomm PMD9635 Firmware
Qualcomm PMD9645 Firmware
Qualcomm PMD9655
Qualcomm PMI8937
Qualcomm PM8952
Qualcomm PM8994 Firmware
Qualcomm PM8996
Qualcomm 8998
Qualcomm PMK8001 Firmware
Qualcomm PMM8996AU
Qualcomm PMX20 firmware
Qualcomm qat3514 firmware
Qualcomm QAT3522 firmware
Qualcomm QAT3550 Firmware
Qualcomm QBT1000 Firmware
Qualcomm qbt1500 firmware
Qualcomm QCA6174A
Qualcomm QCA6174A Firmware
Qualcomm QCA6310 Firmware
Qualcomm QCA6320 Firmware
Qualcomm QCA6564A Firmware
Qualcomm QCA6564A
Qualcomm QCA6574 Firmware
qualcomm qca6574a firmware
Qualcomm QCA6574AU
Qualcomm QCA6584AU firmware
Qualcomm QCA6584AU firmware
Qualcomm QCA9367 Firmware
Qualcomm QCA9377 Firmware
Qualcomm QET4100 Firmware
Qualcomm QET4101 Firmware
Qualcomm QET4200AQ Firmware
Qualcomm QFE1035 Firmware
Qualcomm QFE1040 Firmware
Qualcomm QFE1045 Firmware
Qualcomm QFE2340 Firmware
Qualcomm QFE2550 Firmware
Qualcomm QFE3100 Firmware
Qualcomm QFE3320 Firmware
Qualcomm QFE3335 Firmware
Qualcomm QFE3345 Firmware
Qualcomm QLN1021AQ
Qualcomm qln1030 firmware
Qualcomm QLN1031 Firmware
Qualcomm qln1036aq firmware
Qualcomm QPA4340 Firmware
Qualcomm QPA4360 Firmware
Qualcomm qpa5460 firmware
Qualcomm QSW8573 Firmware
Qualcomm QTC800H Firmware
Qualcomm QTC800S Firmware
Qualcomm QTC800T Firmware
Qualcomm RGR7640AU Firmware
Qualcomm RSW8577
Qualcomm Snapdragon 636
Qualcomm Snapdragon 205
Qualcomm SD210 Firmware
Qualcomm Snapdragon 660
Qualcomm Snapdragon 820
Qualcomm SD821 Firmware
Qualcomm Snapdragon 835
Qualcomm SDM630 Firmware
Qualcomm SDR660
Qualcomm SDW2500
Qualcomm SDW3100 Firmware
Qualcomm SDX20 Firmware
Qualcomm SDX20 Firmware
Qualcomm SMB1350 Firmware
Qualcomm SMB1351 Firmware
Qualcomm SMB1357 Firmware
Qualcomm SMB1358 Firmware
Qualcomm SMB1360 Firmware
Qualcomm SMB1380 Firmware
Qualcomm SMB231 Firmware
Qualcomm SMB358 Firmware
Qualcomm WCD9306
Qualcomm WCD9326 Firmware
Qualcomm WCD9330 Firmware
Qualcomm WCD9335 Firmware
Qualcomm WCD9340 Firmware
Qualcomm WCD9341 Firmware
Qualcomm WCN3610 Firmware
Qualcomm WCN3615 Firmware
Qualcomm WCN3620 Firmware
Qualcomm WCN3660B Firmware
Qualcomm WCN3680B Firmware
Qualcomm WCN3980
Qualcomm WCN3990
Qualcomm WGR7640 Firmware
Qualcomm WSA8810 Firmware
Qualcomm WSA8815 Firmware
Qualcomm WTR2955 Firmware
Qualcomm WTR2965
Qualcomm WTR3905
Qualcomm WTR3925L
Qualcomm WTR3950 Firmware
Qualcomm WTR4905 Firmware
Qualcomm WTR5975 Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2020-11286?

    CVE-2020-11286 has been classified as a high-severity vulnerability due to the potential for unauthorized access and data manipulation.

  • How do I fix CVE-2020-11286?

    To address CVE-2020-11286, ensure that all affected Qualcomm devices are updated with the latest firmware provided by the vendor.

  • Which devices are affected by CVE-2020-11286?

    CVE-2020-11286 affects a range of Qualcomm Snapdragon devices, including models from the Automotive, Consumer IoT, Industrial IoT, and Mobile categories.

  • What causes CVE-2020-11286?

    CVE-2020-11286 is caused by an untrusted pointer dereference that occurs during USB control transfers when multiple requests of different categories are made simultaneously.

  • Is CVE-2020-11286 actively exploited?

    As of the last updates, there is no public indication that CVE-2020-11286 is being actively exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203