First published: Mon Feb 01 2021(Updated: )
An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm apq8009 | ||
qualcomm apq8009w | ||
Qualcomm apq8017 | ||
Qualcomm APQ8053 Firmware | ||
Qualcomm apq8064au | ||
qualcomm apq8076 | ||
Qualcomm apq8096au | ||
Qualcomm Ar8151 | ||
Qualcomm Csr6030 | ||
Qualcomm MDM9206 | ||
Qualcomm Mdm9230 | ||
Qualcomm mdm9250 | ||
Qualcomm Mdm9330 | ||
Qualcomm MDM9607 | ||
Qualcomm Mdm9626 | ||
Qualcomm mdm9628 | ||
Qualcomm Mdm9630 | ||
qualcomm MDM9640 | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9655 | ||
Qualcomm MSM8909W | ||
qualcomm MSM8937 | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm pm660 | ||
Qualcomm pm660a | ||
Qualcomm pm660l | ||
Qualcomm pm8004 | ||
Qualcomm pm8005 | ||
Qualcomm Pm8909 | ||
Qualcomm pm8916 | ||
Qualcomm pm8937 | ||
qualcomm pm8952 | ||
Qualcomm pm8953 | ||
qualcomm pm8956 | ||
Qualcomm Pm8996 | ||
Qualcomm pm8998 | ||
Qualcomm Pmd9607 | ||
Qualcomm Pmd9635 | ||
Qualcomm Pmd9645 | ||
Qualcomm pmd9655 | ||
Qualcomm Pmi8937 | ||
Qualcomm Pmi8952 | ||
Qualcomm Pmi8994 | ||
Qualcomm Pmi8996 | ||
Qualcomm Pmi8998 | ||
Qualcomm Pmk8001 | ||
Qualcomm Pmm8996au | ||
Qualcomm Pmx20 | ||
Qualcomm qat3514 | ||
Qualcomm Qat3522 | ||
Qualcomm Qat3550 | ||
Qualcomm Qbt1000 | ||
Qualcomm Qbt1500 | ||
Qualcomm Qca6174 | ||
Qualcomm qca6174a | ||
qualcomm qca6310 | ||
qualcomm qca6320 | ||
Qualcomm qca6564a | ||
qualcomm qca6564au | ||
qualcomm qca6574 | ||
qualcomm qca6574a | ||
qualcomm qca6574au | ||
qualcomm QCA6584 | ||
qualcomm QCA6584AU | ||
Qualcomm qca9367 | ||
Qualcomm qca9377 | ||
Qualcomm Qet4100 | ||
Qualcomm Qet4101 | ||
Qualcomm Qet4200aq | ||
Qualcomm Qfe1035 | ||
Qualcomm Qfe1040 | ||
Qualcomm Qfe1045 | ||
Qualcomm Qfe2340 | ||
Qualcomm Qfe2550 | ||
Qualcomm Qfe3100 | ||
Qualcomm Qfe3320 | ||
Qualcomm Qfe3335 | ||
Qualcomm Qfe3345 | ||
Qualcomm Qln1021aq | ||
Qualcomm Qln1030 | ||
Qualcomm Qln1031 | ||
Qualcomm Qln1036aq | ||
Qualcomm Qpa4340 | ||
Qualcomm Qpa4360 | ||
Qualcomm Qpa5460 | ||
Qualcomm Qsw8573 | ||
Qualcomm Qtc800h | ||
Qualcomm Qtc800s | ||
Qualcomm Qtc800t | ||
Qualcomm Rgr7640au | ||
Qualcomm Rsw8577 | ||
qualcomm SD 636 | ||
Qualcomm sd205 | ||
Qualcomm sd210 | ||
Qualcomm sd660 | ||
qualcomm sd820 | ||
Qualcomm Sd821 | ||
Qualcomm sd835 | ||
qualcomm SDM630 | ||
Qualcomm Sdr660 | ||
Qualcomm Sdw2500 | ||
Qualcomm Sdw3100 | ||
Qualcomm SDX20 Firmware | ||
Qualcomm Sdx20m | ||
Qualcomm Smb1350 | ||
Qualcomm Smb1351 | ||
Qualcomm Smb1357 | ||
Qualcomm Smb1358 | ||
Qualcomm Smb1360 | ||
Qualcomm Smb1380 | ||
Qualcomm Smb231 | ||
Qualcomm Smb358s | ||
qualcomm wcd9306 | ||
Qualcomm wcd9326 | ||
Qualcomm Wcd9330 | ||
qualcomm wcd9335 | ||
qualcomm wcd9340 | ||
qualcomm wcd9341 | ||
Qualcomm wcn3610 | ||
Qualcomm wcn3615 | ||
Qualcomm Wcn3620 | ||
Qualcomm wcn3660b | ||
Qualcomm wcn3680b | ||
Qualcomm Wcn3980 | ||
qualcomm wcn3990 | ||
Qualcomm Wgr7640 | ||
qualcomm wsa8810 | ||
qualcomm wsa8815 | ||
Qualcomm Wtr2955 | ||
Qualcomm Wtr2965 | ||
Qualcomm Wtr3905 | ||
Qualcomm Wtr3925 | ||
Qualcomm Wtr3950 | ||
Qualcomm Wtr4905 | ||
Qualcomm Wtr5975 | ||
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11286 has been classified as a high-severity vulnerability due to the potential for unauthorized access and data manipulation.
To address CVE-2020-11286, ensure that all affected Qualcomm devices are updated with the latest firmware provided by the vendor.
CVE-2020-11286 affects a range of Qualcomm Snapdragon devices, including models from the Automotive, Consumer IoT, Industrial IoT, and Mobile categories.
CVE-2020-11286 is caused by an untrusted pointer dereference that occurs during USB control transfers when multiple requests of different categories are made simultaneously.
As of the last updates, there is no public indication that CVE-2020-11286 is being actively exploited in the wild.