#VU112424 Improper input validation in Qualcomm products - CVE-2020-11202
Published: July 7, 2025 / Updated: July 7, 2025
Vulnerability identifier: #VU112424
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2020-11202
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerable software:
QCM6125
QCS410
QCS603
QCS610
QCS6125
SA6145P
SA6155
SA8155
SA8155P
SDA640
SDA670
SDM640
SDM830
SDX50M
SDX55M
SM6125
SM6150P
SM6250
SM6250P
SM7125
SM7150P
SM8150P
QCS605
SA6155P
SDA845
SDM670
SDM710
SDM845
SDX55
SM6150
SM7150
SM8150
QCM6125
QCS410
QCS603
QCS610
QCS6125
SA6145P
SA6155
SA8155
SA8155P
SDA640
SDA670
SDM640
SDM830
SDX50M
SDX55M
SM6125
SM6150P
SM6250
SM6250P
SM7125
SM7150P
SM8150P
QCS605
SA6155P
SDA845
SDM670
SDM710
SDM845
SDX55
SM6150
SM7150
SM8150
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Video. A local application can execute arbitrary code.
Remediation
Install security update from vendor's website.