Skip to content
COOEY

EXPOSURES › CVE-2020-11261

CVE-2020-11261

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-11261 ↗
⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatched

Qualcomm Snapdragon chipsets suffered from a memory corruption vulnerability due to improper input validation on large memory allocation requests.

This improper input validation flaw allowed memory corruption when user applications requested huge memory allocations, a vulnerability that was actively exploited in the wild. DIB organizations must ensure their IoT and embedded systems running Qualcomm hardware are patched, as this could lead to system compromise or data exfiltration. The failure highlights the risk of relying on unpatched hardware in critical infrastructure.

Shame score — The vulnerability was actively exploited in the wild and linked to memory corruption, indicating a significant security lapse in Qualcomm's chipsets.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.