CVE-2020-11117
9.8
CRITICAL · CVSS 3.1 · EPSS 19.7% (pctl 97)
Patch early
EPSS 19.7% — above the 10% action threshold.
Description
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ6018, IPQ8064, IPQ8074, QCA4531, QCA9531, QCA9980
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 19.68% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-09-08 |
| Last modified | 2026-06-17 |
Affected (14)
| Vendor | Product |
|---|---|
| qualcomm | ipq4019 |
| qualcomm | ipq4019 firmware |
| qualcomm | ipq6018 |
| qualcomm | ipq6018 firmware |
| qualcomm | ipq8064 |
| qualcomm | ipq8064 firmware |
| qualcomm | ipq8074 |
| qualcomm | ipq8074 firmware |
| qualcomm | qca4531 |
| qualcomm | qca4531 firmware |
| qualcomm | qca9531 |
| qualcomm | qca9531 firmware |
| qualcomm | qca9980 |
| qualcomm | qca9980 firmware |
References
- https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1065
- https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1065
→ the Explorer · watch your stack · NVD