#VU71897 Buffer over-read in Qualcomm products - CVE-2020-11266
Published: February 6, 2023
Vulnerability identifier: #VU71897
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-11266
CWE-ID: CWE-126
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
AR7420
AR9580
CSR8811
IPQ4018
IPQ4028
IPQ4029
QCA10901
QCA4024
QCA7500
QCA7520
QCA7550
QCA8075
QCA9880
QCA9886
QCA9888
QCA9889
QCA9898
QCA9984
QCA9992
QCA9994
QCN3018
QFE1922
QFE1952
WCD9340
WSA8810
IPQ4019
AR7420
AR9580
CSR8811
IPQ4018
IPQ4028
IPQ4029
QCA10901
QCA4024
QCA7500
QCA7520
QCA7550
QCA8075
QCA9880
QCA9886
QCA9888
QCA9889
QCA9898
QCA9984
QCA9992
QCA9994
QCN3018
QFE1922
QFE1952
WCD9340
WSA8810
IPQ4019
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a local application to read and manipulate data.
The vulnerability exists due to improper input validation in Trustzone. A local application can read and manipulate data.
Remediation
Install security update from vendor's website.