CVE-2020-11301
9.1
CRITICAL · CVSS 3.1 · EPSS 11.1% (pctl 96)
Patch early
EPSS 11.1% — above the 10% action threshold.
Description
Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 11.11% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-09-08 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| qualcomm | apq8009 |
| qualcomm | apq8009 firmware |
| qualcomm | apq8017 |
| qualcomm | apq8017 firmware |
| qualcomm | apq8053 |
| qualcomm | apq8053 firmware |
| qualcomm | apq8064au |
| qualcomm | apq8064au firmware |
| qualcomm | apq8096au |
| qualcomm | apq8096au firmware |
| qualcomm | aqt1000 |
| qualcomm | aqt1000 firmware |
| qualcomm | ar7420 |
| qualcomm | ar7420 firmware |
| qualcomm | ar8031 |
| qualcomm | ar8031 firmware |
| qualcomm | ar8035 |
| qualcomm | ar8035 firmware |
| qualcomm | ar9380 |
| qualcomm | ar9380 firmware |
| qualcomm | csr6030 |
| qualcomm | csr6030 firmware |
| qualcomm | csr8811 |
| qualcomm | csr8811 firmware |
| qualcomm | csra6620 |
| qualcomm | csra6620 firmware |
| qualcomm | csra6640 |
| qualcomm | csra6640 firmware |
| qualcomm | csrb31024 |
| qualcomm | csrb31024 firmware |
| qualcomm | ipq4018 |
| qualcomm | ipq4018 firmware |
| qualcomm | ipq4019 |
| qualcomm | ipq4019 firmware |
| qualcomm | ipq4028 |
| qualcomm | ipq4028 firmware |
| qualcomm | ipq4029 |
| qualcomm | ipq4029 firmware |
| qualcomm | ipq5010 |
| qualcomm | ipq5010 firmware |
References
→ the Explorer · watch your stack · NVD