CVE-2020-11117
critical · 9.8u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980
9.8
CVSS
19.7%
EPSS (exploit prob.)
97th
EPSS percentile
2020-09-08
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-77
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| qualcomm | ipq4019_firmware | all versions |
| qualcomm | ipq4019 | all versions |
| qualcomm | ipq6018_firmware | all versions |
| qualcomm | ipq6018 | all versions |
| qualcomm | ipq8064_firmware | all versions |
| qualcomm | ipq8064 | all versions |
| qualcomm | ipq8074_firmware | all versions |
| qualcomm | ipq8074 | all versions |
| qualcomm | qca4531_firmware | all versions |
| qualcomm | qca4531 | all versions |
| qualcomm | qca9531_firmware | all versions |
| qualcomm | qca9531 | all versions |
| qualcomm | qca9980_firmware | all versions |
| qualcomm | qca9980 | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1065
- https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1065
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-11117