← All CVEs

CVE-2020-11117

critical · 9.8

u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980

9.8
CVSS
19.7%
EPSS (exploit prob.)
97th
EPSS percentile
2020-09-08
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
qualcommipq4019_firmwareall versions
qualcommipq4019all versions
qualcommipq6018_firmwareall versions
qualcommipq6018all versions
qualcommipq8064_firmwareall versions
qualcommipq8064all versions
qualcommipq8074_firmwareall versions
qualcommipq8074all versions
qualcommqca4531_firmwareall versions
qualcommqca4531all versions
qualcommqca9531_firmwareall versions
qualcommqca9531all versions
qualcommqca9980_firmwareall versions
qualcommqca9980all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-11117