PT-2020-4935 · Qualcomm · Qca9980+6

Published

2020-09-08

·

Updated

2022-04-28

·

CVE-2020-11117

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Qualcomm products versions IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980
Description: The issue arises from insufficient input validation in the lbd service, allowing an external user to issue a specially crafted debug command. This can result in the overwrite of arbitrary files with arbitrary content, leading to remote code execution.
Recommendations: For Qualcomm products versions IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980, consider disabling the lbd service until a patch is available to prevent remote code execution. Restrict access to the debug command to minimize the risk of exploitation. Avoid using the debug command in the affected service until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05510
CVE-2020-11117

Affected Products

Ipq4019
Ipq6018
Ipq8064
Ipq8074
Qca4531
Qca9531
Qca9980