Untrusted Pointer Dereference in Qualcomm products - CVE-2020-11201

 

Untrusted Pointer Dereference in Qualcomm products - CVE-2020-11201

Published: July 7, 2025


Vulnerability identifier: #VU112423
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11201
CWE-ID: CWE-822
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in Video. A local application can execute arbitrary code.


Affected software

SDM830
SM8150P
SM7150P
SM7125
SM6250P
SM6250
SM6125
SDX55M
SDX50M
QCM6125
SDM640
SDA640
SA8155P
SA8155
SA6155
SA6145P
QCS6125
QCS610
QCS603
QCS410
SM8150
SM7150
SM6150
SDX55
SDM845
SDA845
SA6155P
QCS605

How to mitigate CVE-2020-11201

Install security update from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins