PT-2021-9313 · Qualcomm · Snapdragon Industrial Iot+2
Hhjack
·
Published
2021-03-17
·
Updated
2021-03-25
·
CVE-2020-11305
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Snapdragon Consumer IOT (affected versions not specified)
Snapdragon Industrial IOT (affected versions not specified)
Snapdragon Voice & Music (affected versions not specified)
Description
The issue is related to an integer overflow in boot due to an improper length check on arguments received. This affects Snapdragon Consumer IOT, Snapdragon Industrial IOT, and Snapdragon Voice & Music.
Recommendations
For Snapdragon Consumer IOT, restrict access to the boot process until a proper fix is applied.
For Snapdragon Industrial IOT, consider implementing additional length checks on arguments received during boot as a temporary workaround.
For Snapdragon Voice & Music, avoid using the affected boot process until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Voice & Music