PT-2020-12564 · Qualcomm · Qcm2150+55

Published

2020-11-02

·

Updated

2020-11-09

·

CVE-2020-11125

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Auto versions prior to the fixed version Qualcomm Snapdragon Compute versions prior to the fixed version Qualcomm Snapdragon Connectivity versions prior to the fixed version Qualcomm Snapdragon Consumer IOT versions prior to the fixed version Qualcomm Snapdragon Industrial IOT versions prior to the fixed version Qualcomm Snapdragon Mobile versions prior to the fixed version Qualcomm Snapdragon Voice & Music versions prior to the fixed version Qualcomm Snapdragon Wearables versions prior to the fixed version Qualcomm Snapdragon Wired Infrastructure and Networking versions prior to the fixed version Agatti (affected versions not specified) APQ8009 (affected versions not specified) Bitra (affected versions not specified) IPQ4019 (affected versions not specified) IPQ5018 (affected versions not specified) IPQ6018 (affected versions not specified) IPQ8064 (affected versions not specified) IPQ8074 (affected versions not specified) Kamorta (affected versions not specified) MDM9150 (affected versions not specified) MDM9607 (affected versions not specified) MDM9650 (affected versions not specified) MSM8905 (affected versions not specified) MSM8917 (affected versions not specified) MSM8953 (affected versions not specified) Nicobar (affected versions not specified) QCA6390 (affected versions not specified) QCA9531 (affected versions not specified) QCM2150 (affected versions not specified) QCS404 (affected versions not specified) QCS405 (affected versions not specified) QCS605 (affected versions not specified) QCS610 (affected versions not specified) QM215 (affected versions not specified) QRB5165 (affected versions not specified) Rennell (affected versions not specified) SA415M (affected versions not specified) SA515M (affected versions not specified) SA6155P (affected versions not specified) SA8155P (affected versions not specified) Saipan (affected versions not specified) SC8180X (affected versions not specified) SDM429 (affected versions not specified) SDM429W (affected versions not specified) SDM439 (affected versions not specified) SDM450 (affected versions not specified) SDM632 (affected versions not specified) SDM660 (affected versions not specified) SDM670 (affected versions not specified) SDM710 (affected versions not specified) SDM845 (affected versions not specified) SDX55 (affected versions not specified) SM6150 (affected versions not specified) SM7150 (affected versions not specified) SM8150 (affected versions not specified) SM8250 (affected versions not specified) SXR1130 (affected versions not specified) SXR2130 (affected versions not specified)
Description The issue is related to out of bound access in the MHI command process due to a lack of check of the channel id value received from MHI devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11125

Affected Products

Apq8009
Agatti
Bitra
Ipq4019
Ipq5018
Ipq6018
Ipq8064
Ipq8074
Kamorta
Mdm9150
Mdm9607
Mdm9650
Msm8905
Msm8917
Msm8953
Nicobar
Qca6390
Qca9531
Qcm2150
Qcs404
Qcs405
Qcs605
Qcs610
Qm215
Qrb5165
Qualcomm Snapdragon Auto
Qualcomm Snapdragon Compute
Qualcomm Snapdragon Connectivity
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Industrial Iot
Qualcomm Snapdragon Mobile
Qualcomm Snapdragon Voice & Music
Qualcomm Snapdragon Wearables
Qualcomm Snapdragon Wired Infrastructure/Networking
Rennell
Sa415M
Sa515M
Sa6155P
Sa8155P
Sc8180X
Sdm429
Sdm439
Sdm450
Sdm632
Sdm660
Sdm670
Sdm710
Sdm845
Sdx55
Sm6150
Sm7150
Sm8150
Sm8250
Sxr1130
Sxr2130
Saipan