ID

VAR-202101-0101


CVE

CVE-2020-11217


TITLE

plural  Qualcomm  Product Double Release Vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2020-015560

DESCRIPTION

A possible double free or invalid memory access in audio driver while reading Speaker Protection parameters in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile. plural Qualcomm The product contains a double release vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. The Qualcomm chip is a chip of Qualcomm (Qualcomm). A way to miniaturize circuits (mainly including semiconductor equipment, but also passive components, etc.) and often manufactured on the surface of semiconductor wafers

Trust: 2.25

sources: NVD: CVE-2020-11217 // JVNDB: JVNDB-2020-015560 // CNNVD: CNNVD-202012-499 // VULMON: CVE-2020-11217

IOT TAXONOMY

category:['other device', 'embedded device']sub_category:SoC

Trust: 0.1

category:['other device', 'embedded device']sub_category:general

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:qualcommmodel:wcn3910scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wsa8815scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wtr2965scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa5461scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdr735gscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm4630scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm8830scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm2301scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pmx55scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qtc800hscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa4340scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd768gscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa8802scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5657scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat3516scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdr735scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9375scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8150ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm6621scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pmr735bscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8250scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca6391scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd765scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sm4125scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smr546scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn6740scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd6905gscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm6350scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm2305scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa8821scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qtc801sscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8350cscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm5677scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sm7250pscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qtc800sscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm5670scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qbt2000scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa8842scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9370scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm7250scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn3991scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm4125scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn6851scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qet4100scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm5679scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca6431scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat3550scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm4650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn3980scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcs2290scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qet4101scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm3301scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa4360scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdxr25gscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm660ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm5652scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pmk8003scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn6750scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm5671scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm4641scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smb1395scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qfs2630scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd765gscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5875scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdr425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn3998scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qfs2608scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa2625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pmk8350scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smr525scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm6670scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8150lscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pmk7350scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qln5020scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qln4642scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa6560scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wgr7640scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sm4350scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smr545scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa5581scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smb1390scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wsa8830scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd750gscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn3990scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9341scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wsa8810scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm4621scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa8803scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8350scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca6436scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcm4290scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8150cscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat5533scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9380scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qet6110scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smb1354scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn6850scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qet5100scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa5580scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sm7350scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn3950scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat3518scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat5516scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat3514scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm7150ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm5621scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smb1351scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qet6100scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm6150lscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm4640scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat5515scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm4650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm8820scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5679scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm6585scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd460scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qfs2530scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm5579scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm2307scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9335scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm4643scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smb1355scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa8801scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm8895scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5670scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wsa8835scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm7350cscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wtr3925scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat3519scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca6390scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm5620scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm6582scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smb1394scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcd9385scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5620scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm6150ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm660lscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm2310scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qln5030scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm3302scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5677scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5621scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm3003ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qfs2580scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat3555scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn3988scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qln4650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pmk8002scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5641scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdr865scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smb1396scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8350bscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd8885gscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm7150lscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qln5040scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smb1398scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qet5100mscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8009scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qsm7250scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm5650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat3522scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:wcn6856scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8150bscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qdm2308scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa8673scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8008scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pmi632scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdx55mscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pmr525scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca6426scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcm2290scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdr660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5658scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat5522scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd662scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd8655gscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:rsw8577scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm7250bscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8350bhscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm8870scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm6125scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qtm525scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:smr526scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pm8350bhsscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpa8686scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qpm5870scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdr8250scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca6421scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:pmr735ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qat5568scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcs4290scope:eqversion: -

Trust: 1.0

vendor:クアルコムmodel:pm4125scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:pm6150lscope: - version: -

Trust: 0.8

vendor:クアルコムmodel:pm6150ascope: - version: -

Trust: 0.8

vendor:クアルコムmodel:pm660ascope: - version: -

Trust: 0.8

vendor:クアルコムmodel:pm6350scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:pm660scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:pm6125scope: - version: -

Trust: 0.8

vendor:クアルコムmodel:pm3003ascope: - version: -

Trust: 0.8

vendor:クアルコムmodel:pm660lscope: - version: -

Trust: 0.8

vendor:クアルコムmodel:pm7150ascope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-015560 // NVD: CVE-2020-11217

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-11217
value: HIGH

Trust: 1.0

NVD: CVE-2020-11217
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202012-499
value: HIGH

Trust: 0.6

VULMON: CVE-2020-11217
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-11217
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2020-11217
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2020-11217
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULMON: CVE-2020-11217 // JVNDB: JVNDB-2020-015560 // CNNVD: CNNVD-202012-499 // NVD: CVE-2020-11217

PROBLEMTYPE DATA

problemtype:CWE-415

Trust: 1.0

problemtype:Double release (CWE-415) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-015560 // NVD: CVE-2020-11217

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202012-499

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-202012-499

PATCH

title:December 2020 Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins/december-2020-security-bulletin

Trust: 0.8

title:Google Android Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=136016

Trust: 0.6

sources: JVNDB: JVNDB-2020-015560 // CNNVD: CNNVD-202012-499

EXTERNAL IDS

db:NVDid:CVE-2020-11217

Trust: 2.6

db:JVNDBid:JVNDB-2020-015560

Trust: 0.8

db:CNNVDid:CNNVD-202012-499

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2020-11217

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2020-11217 // JVNDB: JVNDB-2020-015560 // CNNVD: CNNVD-202012-499 // NVD: CVE-2020-11217

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin

Trust: 1.7

url:https://www.qualcomm.com/company/product-security/bulletins/december-2020-security-bulletin

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-11217

Trust: 1.4

url:https://vigilance.fr/vulnerability/google-android-pixel-multiple-vulnerabilities-of-december-2020-34050

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/415.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2020-11217 // JVNDB: JVNDB-2020-015560 // CNNVD: CNNVD-202012-499 // NVD: CVE-2020-11217

SOURCES

db:OTHERid: -
db:VULMONid:CVE-2020-11217
db:JVNDBid:JVNDB-2020-015560
db:CNNVDid:CNNVD-202012-499
db:NVDid:CVE-2020-11217

LAST UPDATE DATE

2025-01-30T22:16:21.490000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2020-11217date:2021-01-29T00:00:00
db:JVNDBid:JVNDB-2020-015560date:2021-10-04T09:06:00
db:CNNVDid:CNNVD-202012-499date:2021-07-09T00:00:00
db:NVDid:CVE-2020-11217date:2024-11-21T04:57:17.133

SOURCES RELEASE DATE

db:VULMONid:CVE-2020-11217date:2021-01-21T00:00:00
db:JVNDBid:JVNDB-2020-015560date:2021-10-04T00:00:00
db:CNNVDid:CNNVD-202012-499date:2020-12-08T00:00:00
db:NVDid:CVE-2020-11217date:2021-01-21T10:15:14.823