Time-of-check Time-of-use (TOCTOU) Race Condition in Qualcomm products - CVE-2020-11233

 

Time-of-check Time-of-use (TOCTOU) Race Condition in Qualcomm products - CVE-2020-11233

Published: February 6, 2023


Vulnerability identifier: #VU71899
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11233
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation in Boot. A local application can gain access to sensitive information.


Affected software

QLN1030
SDW3100
SDW2500
SD820
SD439
RGR7640AU
Qualcomm215
QTC801S
QSW8573
QLN1036AQ
QLN1031
SDX20M
QLN1021AQ
QFE3345
QFE3335
QFE3320
QFE3100
QFE2550
QFE2340
QFE1045
QFE1040
QFE1035
QET4200AQ
QET4101
QET4100
WCN3615
WTR5975
WTR4905
WTR3925
WTR3905
WTR2965
WTR2955
WSA8815
WSA8810
WGR7640
WCN3680B
WCN3680
WCN3660B
WCN3620
QCC112
WCN3610
WCD9335
WCD9330
WCD9326
WCD9306
SMB358S
SMB231
SMB1360
SMB1358
SMB1357
SMB1355
SMB1351
SMB1350
MDM9630
PM8937
PM8916
PM8909
PM8004
PM660
PM439
PM215
MDM9655
PM8952
MDM9628
MDM9626
MDM9330
MDM9250
MDM9230
CSR6030
APQ8076
APQ8009W
PMM8996AU
QCC1110
QCA9367
QCA6584
QCA6574A
QCA6564AU
QCA6564A
QCA6174
QCA4020
PMX20
PMK8001
PMI8996
PMI8994
PMI8952
PMI8937
PMI632
PMD9655
PMD9645
PMD9635
PMD9607
PM8996
PM8956
PM8953
SDX20
SD210
SD205
MSM8996AU
MSM8937
MSM8909W
MDM9650
MDM9640
MDM9607
MDM9206
APQ8096AU
APQ8053
APQ8017
QCA9379
QCA9377
QCA6574AU
QCA6174A
APQ8009

How to mitigate CVE-2020-11233

Install security update from vendor's website.


External References

Related Security Bulletins