An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
Metrics
No CVSS v4.0
Attack Vector Physical
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.00045.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Qualcomm
Subscribe
|
Apq8009
Subscribe
Apq8009w
Subscribe
Apq8017
Subscribe
Apq8053
Subscribe
Apq8064au
Subscribe
Apq8076
Subscribe
Apq8096au
Subscribe
Ar8151
Subscribe
Csr6030
Subscribe
Mdm9206
Subscribe
Mdm9230
Subscribe
Mdm9250
Subscribe
Mdm9330
Subscribe
Mdm9607
Subscribe
Mdm9626
Subscribe
Mdm9628
Subscribe
Mdm9630
Subscribe
Mdm9640
Subscribe
Mdm9650
Subscribe
Mdm9655
Subscribe
Msm8909w
Subscribe
Msm8937
Subscribe
Msm8996au
Subscribe
Pm660
Subscribe
Pm660a
Subscribe
Pm660l
Subscribe
Pm8004
Subscribe
Pm8005
Subscribe
Pm8909
Subscribe
Pm8916
Subscribe
Pm8937
Subscribe
Pm8952
Subscribe
Pm8953
Subscribe
Pm8956
Subscribe
Pm8996
Subscribe
Pm8998
Subscribe
Pmd9607
Subscribe
Pmd9635
Subscribe
Pmd9645
Subscribe
Pmd9655
Subscribe
Pmi8937
Subscribe
Pmi8952
Subscribe
Pmi8994
Subscribe
Pmi8996
Subscribe
Pmi8998
Subscribe
Pmk8001
Subscribe
Pmm8996au
Subscribe
Pmx20
Subscribe
Qat3514
Subscribe
Qat3522
Subscribe
Qat3550
Subscribe
Qbt1000
Subscribe
Qbt1500
Subscribe
Qca6174
Subscribe
Qca6174a
Subscribe
Qca6310
Subscribe
Qca6320
Subscribe
Qca6564a
Subscribe
Qca6564au
Subscribe
Qca6574
Subscribe
Qca6574a
Subscribe
Qca6574au
Subscribe
Qca6584
Subscribe
Qca6584au
Subscribe
Qca9367
Subscribe
Qca9377
Subscribe
Qet4100
Subscribe
Qet4101
Subscribe
Qet4200aq
Subscribe
Qfe1035
Subscribe
Qfe1040
Subscribe
Qfe1045
Subscribe
Qfe2340
Subscribe
Qfe2550
Subscribe
Qfe3100
Subscribe
Qfe3320
Subscribe
Qfe3335
Subscribe
Qfe3345
Subscribe
Qln1021aq
Subscribe
Qln1030
Subscribe
Qln1031
Subscribe
Qln1036aq
Subscribe
Qpa4340
Subscribe
Qpa4360
Subscribe
Qpa5460
Subscribe
Qsw8573
Subscribe
Qtc800h
Subscribe
Qtc800s
Subscribe
Qtc800t
Subscribe
Rgr7640au
Subscribe
Rsw8577
Subscribe
Sd205
Subscribe
Sd210
Subscribe
Sd660
Subscribe
Sd820
Subscribe
Sd821
Subscribe
Sd835
Subscribe
Sd 636
Subscribe
Sdm630
Subscribe
Sdr660
Subscribe
Sdw2500
Subscribe
Sdw3100
Subscribe
Sdx20
Subscribe
Sdx20m
Subscribe
Smb1350
Subscribe
Smb1351
Subscribe
Smb1357
Subscribe
Smb1358
Subscribe
Smb1360
Subscribe
Smb1380
Subscribe
Smb231
Subscribe
Smb358s
Subscribe
Wcd9306
Subscribe
Wcd9326
Subscribe
Wcd9330
Subscribe
Wcd9335
Subscribe
Wcd9340
Subscribe
Wcd9341
Subscribe
Wcn3610
Subscribe
Wcn3615
Subscribe
Wcn3620
Subscribe
Wcn3660b
Subscribe
Wcn3680b
Subscribe
Wcn3980
Subscribe
Wcn3990
Subscribe
Wgr7640
Subscribe
Wsa8810
Subscribe
Wsa8815
Subscribe
Wtr2955
Subscribe
Wtr2965
Subscribe
Wtr3905
Subscribe
Wtr3925
Subscribe
Wtr3950
Subscribe
Wtr4905
Subscribe
Wtr5975
Subscribe
|
Configuration 1 [-]
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-3640 | An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qualcomm
Published:
Updated: 2024-08-04T11:28:13.808Z
Reserved: 2020-03-31T00:00:00
Link: CVE-2020-11286
No data.
Status : Modified
Published: 2021-02-22T07:15:15.143
Modified: 2024-11-21T04:57:44.147
Link: CVE-2020-11286
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD