Improper Access Control in Qualcomm products - CVE-2020-11303

 

Improper Access Control in Qualcomm products - CVE-2020-11303

Published: February 6, 2023


Vulnerability identifier: #VU71905
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11303
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation in WLAN. A remote attacker can gain access to sensitive information.


Affected software

SA515M
SD820
SA8195P
SA8155P
SA8155
SA8150P
SA8145P
SA6155
SA6150P
SA6145P
SD821
QCA9886
QCA9378A
QCA9369
QCA9367
QCA6696
QCA6595AU
QCA6595
WCD9341
WSA8815
WSA8810
WCN3999
WCN3998
WCN3990
WCN3980
WCN3680B
WCN3660B
WCN3615
WCN3610
WCD9360
QCA6584AU
WCD9340
WCD9335
WCD9330
WCD9326
SDX20M
SDX12
MDM8215
MDM9645
MDM9628
MDM9626
MDM9615
MDM9310
MDM9250
MDM9215
MDM9655
CSRA6640
CSRA6620
CSR6030
AR8031
APQ8094
APQ8092
APQ8076
APQ8064AU
QCA6175A
QCA6584
QCA6574A
QCA6574
QCA6564AU
QCA6564A
QCA6564
QCA6320
QCA6310
QCA6234
QCA6174
QCA4020
QCA1990
QCA1023
QCA0000
MSM8994
MSM8992
MSM8976
SD210
SA6155P
QCS405
QCA9379
QCA9377
SDX55
SDX24
SDX20
SD845
MDM9650
MDM9640
MDM9607
MDM9206
APQ8096AU
APQ8053
QCA6574AU
APQ8009
QCA6174A
MSM8996AU

How to mitigate CVE-2020-11303

Install security update from vendor's website.


External References

Related Security Bulletins