CVE-2020-11206 is a buffer overflow vulnerability in Qualcomm's Fastrpc component, affecting numerous Snapdragon Auto, Compute, Consumer IoT, Industrial IoT, and Mobile platforms due to insufficient validation of input parameters. This flaw carries a CVSS score of 7.8 (High), indicating that a local attacker with low privileges could achieve high impact on confidentiality, integrity, and availability. While there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community discussion and media coverage, with reports suggesting nearly 50% of all smartphones could be affected. Despite the high potential impact and widespread affected products, it is not currently listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:apq8098_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:msm8998_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:qcm4290_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:qcm6125_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:qcs410_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.