ZeroHour

CVE-2020-11220

CVSS 3.1
6.4 medium
EPSS
<1%p3
Published
()
Modified
Description

While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

Vendors
qualcomm
Products
aqt1000 firmware, ar8035 firmware, pm4125 firmware, pm4250 firmware, pm6125 firmware, pm6150 firmware, pm6150a firmware, pm6150l firmware, pm6350 firmware, pm640a firmware, pm640l firmware, pm640p firmware
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news