Home / Vulnerabilities / CVE-2020-11261
HIGH SEVERITY
CVE-2020-11261 Qualcomm · Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Qualcomm Multiple Chipsets Improper Input Validation Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
7.8 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Likelihood

EPSS Prediction

1.14 %
Predictive Probability
Percentile Rank
78.1 th

Documented as more likely to be exploited than 78.1% of known CVEs.

Detection Date

Dec 01, 2021

Remediation Due

Jun 01, 2022

CISA Catalog Active

Threat Analysis

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Remediation Directive

Apply updates per vendor instructions.

External Intelligence