CVE-2020-11255
Published: 07 April 2021
Summary
CVE-2020-11255 is a high-severity Missing Release of Memory after Effective Lifetime (CWE-401) vulnerability in Qualcomm Sdx55 Firmware. Its CVSS base score is 7.5 (High).
Operationally, ranked at the 48.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-3609
Vulnerability details
Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of the memory is leaked in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…
more
Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.