#VU112433 Buffer overflow in Qualcomm products - CVE-2020-11130
Published: July 7, 2025
Vulnerability identifier: #VU112433
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-11130
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
QCM4290
QCS4290
QSM8350
SA6145P
SA6155
SA8155
SA8155P
SC8180XP
SDX55M
SM4250
SM4250P
SM6115
SM6115P
SM6125
SM6250
SM6350
SM7125
SM7225
SM7250
SM7250P
SM8150P
SM8350
SM8350P
SXR2130P
QM215
SA6155P
SC8180X
SDX55
SM8150
SM8250
SXR2130
QCM4290
QCS4290
QSM8350
SA6145P
SA6155
SA8155
SA8155P
SC8180XP
SDX55M
SM4250
SM4250P
SM6115
SM6115P
SM6125
SM6250
SM6350
SM7125
SM7225
SM7250
SM7250P
SM8150P
SM8350
SM8350P
SXR2130P
QM215
SA6155P
SC8180X
SDX55
SM8150
SM8250
SXR2130
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation in WLAN. A local privileged application can execute arbitrary code.
Remediation
Install security update from vendor's website.