CVE-2020-11137
Published: 21 January 2021
Summary
CVE-2020-11137 is a critical-severity Integer Overflow or Wraparound (CWE-190) vulnerability in Qualcomm Apq8009. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 43.6% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-3491
Vulnerability details
Integer multiplication overflow resulting in lower buffer size allocation than expected causes memory access out of bounds resulting in possible device instability in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…
more
Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.