CWE
119
Advisory Published
CVE Published
Updated

CVE-2020-11286: Buffer Overflow

First published: Mon Feb 01 2021(Updated: )

An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Credit: product-security@qualcomm.com

Affected SoftwareAffected VersionHow to fix
Qualcomm apq8009
qualcomm apq8009w
Qualcomm apq8017
Qualcomm APQ8053 Firmware
Qualcomm apq8064au
qualcomm apq8076
Qualcomm apq8096au
Qualcomm Ar8151
Qualcomm Csr6030
Qualcomm MDM9206
Qualcomm Mdm9230
Qualcomm mdm9250
Qualcomm Mdm9330
Qualcomm MDM9607
Qualcomm Mdm9626
Qualcomm mdm9628
Qualcomm Mdm9630
qualcomm MDM9640
Qualcomm MDM9650
Qualcomm MDM9655
Qualcomm MSM8909W
qualcomm MSM8937
Qualcomm MSM8996AU Firmware
Qualcomm pm660
Qualcomm pm660a
Qualcomm pm660l
Qualcomm pm8004
Qualcomm pm8005
Qualcomm Pm8909
Qualcomm pm8916
Qualcomm pm8937
qualcomm pm8952
Qualcomm pm8953
qualcomm pm8956
Qualcomm Pm8996
Qualcomm pm8998
Qualcomm Pmd9607
Qualcomm Pmd9635
Qualcomm Pmd9645
Qualcomm pmd9655
Qualcomm Pmi8937
Qualcomm Pmi8952
Qualcomm Pmi8994
Qualcomm Pmi8996
Qualcomm Pmi8998
Qualcomm Pmk8001
Qualcomm Pmm8996au
Qualcomm Pmx20
Qualcomm qat3514
Qualcomm Qat3522
Qualcomm Qat3550
Qualcomm Qbt1000
Qualcomm Qbt1500
Qualcomm Qca6174
Qualcomm qca6174a
qualcomm qca6310
qualcomm qca6320
Qualcomm qca6564a
qualcomm qca6564au
qualcomm qca6574
qualcomm qca6574a
qualcomm qca6574au
qualcomm QCA6584
qualcomm QCA6584AU
Qualcomm qca9367
Qualcomm qca9377
Qualcomm Qet4100
Qualcomm Qet4101
Qualcomm Qet4200aq
Qualcomm Qfe1035
Qualcomm Qfe1040
Qualcomm Qfe1045
Qualcomm Qfe2340
Qualcomm Qfe2550
Qualcomm Qfe3100
Qualcomm Qfe3320
Qualcomm Qfe3335
Qualcomm Qfe3345
Qualcomm Qln1021aq
Qualcomm Qln1030
Qualcomm Qln1031
Qualcomm Qln1036aq
Qualcomm Qpa4340
Qualcomm Qpa4360
Qualcomm Qpa5460
Qualcomm Qsw8573
Qualcomm Qtc800h
Qualcomm Qtc800s
Qualcomm Qtc800t
Qualcomm Rgr7640au
Qualcomm Rsw8577
qualcomm SD 636
Qualcomm sd205
Qualcomm sd210
Qualcomm sd660
qualcomm sd820
Qualcomm Sd821
Qualcomm sd835
qualcomm SDM630
Qualcomm Sdr660
Qualcomm Sdw2500
Qualcomm Sdw3100
Qualcomm SDX20 Firmware
Qualcomm Sdx20m
Qualcomm Smb1350
Qualcomm Smb1351
Qualcomm Smb1357
Qualcomm Smb1358
Qualcomm Smb1360
Qualcomm Smb1380
Qualcomm Smb231
Qualcomm Smb358s
qualcomm wcd9306
Qualcomm wcd9326
Qualcomm Wcd9330
qualcomm wcd9335
qualcomm wcd9340
qualcomm wcd9341
Qualcomm wcn3610
Qualcomm wcn3615
Qualcomm Wcn3620
Qualcomm wcn3660b
Qualcomm wcn3680b
Qualcomm Wcn3980
qualcomm wcn3990
Qualcomm Wgr7640
qualcomm wsa8810
qualcomm wsa8815
Qualcomm Wtr2955
Qualcomm Wtr2965
Qualcomm Wtr3905
Qualcomm Wtr3925
Qualcomm Wtr3950
Qualcomm Wtr4905
Qualcomm Wtr5975
Android

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2020-11286?

    CVE-2020-11286 has been classified as a high-severity vulnerability due to the potential for unauthorized access and data manipulation.

  • How do I fix CVE-2020-11286?

    To address CVE-2020-11286, ensure that all affected Qualcomm devices are updated with the latest firmware provided by the vendor.

  • Which devices are affected by CVE-2020-11286?

    CVE-2020-11286 affects a range of Qualcomm Snapdragon devices, including models from the Automotive, Consumer IoT, Industrial IoT, and Mobile categories.

  • What causes CVE-2020-11286?

    CVE-2020-11286 is caused by an untrusted pointer dereference that occurs during USB control transfers when multiple requests of different categories are made simultaneously.

  • Is CVE-2020-11286 actively exploited?

    As of the last updates, there is no public indication that CVE-2020-11286 is being actively exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203