ZeroHour

CVE-2020-11178

CVSS 3.1
7.8 high
EPSS
<1%p5
Published
()
Modified
Description

Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memory and its RoT memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

Vendors
qualcomm
Products
aqt1000 firmware, ar8031 firmware, ar8035 firmware, csra6620 firmware, csra6640 firmware, csrb31024 firmware, fsm10055 firmware, fsm10056 firmware, mdm9205 firmware, pm3003a firmware, pm4125 firmware, pm456 firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.