Vulnerability
CVE-2020-11132
Component: BOOT
Location: FIRMWARE
u'Buffer over read in boot due to size check ignored before copying GUID attribute from request to response' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096AU, APQ8098, MDM8207, MDM9150, MDM9205, MDM9206, MDM9207, MDM9250, MDM9607, MDM9628, MDM9650, MSM8108, MSM8208, MSM8209, MSM8608, MSM8905, MSM8909, MSM8998, QCM4290, QCS405, QCS410, QCS4290, QCS603, QCS605, QCS610, QSM8250, SA415M, SA515M, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SC8180X, SC8180X+SDX55, SC8180XP, SDA640, SDA670, SDA845, SDA855, SDM1000, SDM640, SDM670, SDM710, SDM712, SDM830, SDM845, SDM850, SDX24, SDX50M, SDX55, SDX55M, SM4125, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SXR1120, SXR1130, SXR2130, SXR2130P, WCD9330
Impact
Severity (Manufact.)
MEDIUM
Severity (NIST)
7.1
Severity (Android)
N/A
Chipsets
19
Devices
723
Affected Hardware
Name | Also known as | Manufacturer |
---|---|---|
MSM8905 | Qualcomm 205 | Qualcomm |
MSM8208 | Snapdragon 208 | Qualcomm |
MSM8909 | Snapdragon 210 | Qualcomm |
SM6115 | Snapdragon 662 | Qualcomm |
SM6125 | Snapdragon 665 | Qualcomm |
SDM670 | Snapdragon 670 | Qualcomm |
SM6150 | Snapdragon 675 | Qualcomm |
SM6350 | Snapdragon 690 | Qualcomm |
SDM710 | Snapdragon 710 | Qualcomm |
SDM712 | Snapdragon 712 | Qualcomm |
19 of 19 row(s) shown.
Rows per page
Page 1 of 2
Information reliability
The information on this website is intended to provide information on the big picture of chipset security and measure trends within the industry. Our information is obtained from several vantage points, checked for consistency, and automatically cross-referenced. However, this process may not always yield reliable information. Do not use the information on a particular vulnerability, chipset or device to verify your individual exposure in cases where inaccuracies are inacceptable, for instance to assess risks if you are a Politically Exposed Person.
Timeline
Introduced (est):
Jan 1, 2014
Reported:
Jan 20, 2020
Advisory Published:
Nov 2, 2020
CVE Published:
Nov 12, 2020
Android Patch Level:
None