{"id": "CVE-2020-11130", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.6, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.8}]}, "published": "2020-11-12T10:15:12.157", "references": [{"url": "https://www.qualcomm.com/company/product-security/bulletins/november-2020-bulletin", "tags": ["Vendor Advisory"], "source": "product-security@qualcomm.com"}, {"url": "https://www.qualcomm.com/company/product-security/bulletins/november-2020-bulletin", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-120"}]}], "descriptions": [{"lang": "en", "value": "u'Possible buffer overflow in WIFI hal process due to copying data without checking the buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile in QCM4290, QCS4290, QM215, QSM8350, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SC8180X, SC8180XP, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6250, SM6350, SM7125, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P"}, {"lang": "es", "value": "Un posible desbordamiento del b\u00fafer en el proceso de WIFI hal debido a una copia de datos sin comprobar la longitud del b\u00fafer en los productos Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile en versiones QCM4290, QCS4290, QM215, QSM8350, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SC8180X, SC8180XP, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6250, SM6350, SM7125, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P"}], "lastModified": "2024-11-21T04:56:53.337", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:qcm4290_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C7FFB96-53E7-41A2-BC99-7ACD853214A8"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:qcm4290:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "74EBA77E-69A5-4145-9BEC-CD39BA132309"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:qcs4290_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06789CB9-E6FA-400D-90B6-C2DB6C8EF153"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:qcs4290:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FFCB9F22-57F2-4327-95B9-B2342A02E45E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:qm215_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F18CD1F1-C36A-4840-88CD-8F00BD68EF1A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:qm215:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6A01800E-994E-4095-AD86-F02DC9D9C86E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:qsm8350_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1894F6B9-31DA-44E8-AA28-064F73EBEE8D"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:qsm8350:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8AA23845-D9F5-4035-8A93-F475D865586F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sa6145p_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C66671C1-AE1A-44BE-9DB2-0B09FF4417DB"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sa6145p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "74AA3929-3F80-4D54-B13A-9B070D5C03BB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sa6155_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4C40544E-B040-491C-8DF3-50225E70B50C"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sa6155:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A2DAC85C-CDC9-4784-A69A-147A2CE8A8B2"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8DC40C14-3B2D-4E00-9E0F-86E6BDBF2D81"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sa6155p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0514D433-162C-4680-8912-721D19BE6201"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sa8155_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F33EB594-B0D3-42F2-B1CA-B0E6C9D82C6B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sa8155:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "50EF47E5-2875-412F-815D-44804BB3A739"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8648B38-2597-401A-8F53-D582FA911569"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sa8155p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A01CD59B-8F21-4CD6-8A1A-7B37547A8715"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sc8180x_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30A45C1A-C921-42B5-9237-367245023B45"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sc8180x:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "56C9D979-F214-4CD4-8CF9-43BC804BB179"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sc8180xp_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "647A964A-37C7-403E-82EF-BE88A1E89CA9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sc8180xp:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "594AAEC3-ADCE-4448-9CED-462DA162F906"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E93FB34B-3674-404D-9687-E092E9A246AB"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sdx55:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F3FF5A9A-A34A-499C-B6E0-D67B496C5454"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sdx55m_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B726BE34-E18B-4A88-B8E6-778215FD419E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sdx55m:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "585B794A-0674-418B-B45B-42EA97C40B9F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm4250_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "52C376CE-BAE9-40DD-86B4-D548FE521DD3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm4250:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "97B16DE3-711D-4BEF-947B-5E9299EA3BF9"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm4250p_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D37597E0-18EE-4565-B050-67BB0DEA9192"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm4250p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6BC3822F-7BB0-4F6F-B62C-3536A2E9E715"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm6115_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00202FB3-C77E-4116-B5C7-C0EF172C2380"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm6115:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "14B4CE11-4AB2-4395-86C0-063C396FE836"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm6115p_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D512B999-6E23-4DEA-A259-BA3DBB61242E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm6115p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "71D6D9B0-64E8-428D-A513-CD6DD3A9A353"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm6125_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE529BF7-0C9B-4B79-ABF8-54D5051F5E94"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm6125:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "124227C1-DC7A-4A44-A513-C83976464BD3"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm6250_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FACA2BF1-85D3-447F-A08D-B90330A22550"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm6250:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C2ABA18D-82C1-4366-B1D7-DED42DD3D5C5"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm6350_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80E5A7CE-9356-4E00-8458-52C60CB34753"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm6350:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "571CC514-7B65-4769-9921-149ABFF2FE74"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm7125_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "055E464C-C63A-455E-97B0-0D8A266A428F"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm7125:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "527A0A00-0C6C-4937-87A3-00668CF7BACB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm7225_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34E2940C-5D85-4D05-A1B1-41E20DF01626"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm7225:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CAD2B248-B205-4D7A-B03B-9AC3CEFF8760"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm7250_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A39DE400-ECBB-457C-AAE9-D473829DB424"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm7250:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "240DA0AC-6AC3-48EF-AF50-4DA788035D7E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm7250p_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "76DB5472-DF51-4144-8A69-9B231CF782DA"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm7250p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1D395018-251C-45AA-9EE8-A638CAB0B508"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm8150_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9286B1E8-E39F-4DAA-8969-311CA2A0A8AA"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm8150:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "19B9AE36-87A9-4EE7-87C8-CCA2DCF51039"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm8150p_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80CEB8B9-7296-451F-B3B8-1C68392F0996"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm8150p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7A3C851A-205F-42FC-88D2-58C613EDDD41"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm8250_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDC730C6-FB32-4566-AAE2-B2B261BA9411"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm8250:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5A432773-467F-492C-AA3A-ADF08A21FB3F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm8350_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B0798E6-68B1-4C0E-BF5B-5BC8033351A5"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm8350:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7E70D909-40D1-4B66-AEA3-034F2C53FB0F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sm8350p_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "843EA485-D423-467E-B058-0A592C8F1E23"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sm8350p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0779F521-F94A-4641-B5B2-C7611A8382C5"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sxr2130_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9F9FA3B1-E4E4-4D9B-A99C-7BF958D4B993"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sxr2130:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "95762B01-2762-45BD-8388-5DB77EA6139C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sxr2130p_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2AC910FA-0AD1-460A-B333-57C99D4FC7BB"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sxr2130p:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "34DFEB6B-7D74-4DEE-A263-49D9420DB126"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "product-security@qualcomm.com"}