Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052, APQ8056, APQ8076, APQ8096, APQ8096SG, APQ8098, MDM9655, MSM8952, MSM8956, MSM8976, MSM8976SG, MSM8996, MSM8996SG, MSM8998, QCM4290, QCM6125, QCS410, QCS4290, QCS610, QCS6125, QSM8250, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SDA640, SDA660, SDA845, SDA855, SDM640, SDM660, SDM830, SDM845, SDM850, SDX50M, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SXR2130, SXR2130P
総合評価: CVE-2020-11207 は悪用リスクが高い(72.2/100)。CVSS 深刻度は高。悪用される可能性が高い(EPSS 1.47%、70 パーセンタイル) 根拠: 公開エクスプロイトが 1 件参照されています(Exploit-DB)。 直近 1 日で EPSS が +1.41% 上昇。悪用への関心が高まっている可能性があります。 推奨対応: 公開エクスプロイトが確認されています。影響範囲の確認、緩和策の適用、パッチ適用を優先してください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
| EDB-ID | ソース | 種別 | 公開 | リンク |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.06% | 1.47% | +1.41% |
| 2 | 2025-11-21 | 0.04% | 0.06% | +0.02% |
| 3 | 2025-11-18 | — | 0.04% | — |
EPSS の全履歴 (全 14 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 7.2 | 2.0 | HIGH |
|
3.9 | 10.0 | [email protected] |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| qualcomm | apq8052_firmware | — | cpe:2.3:o:qualcomm:apq8052_firmware:-:*:*:*:*:*:*:* |
| qualcomm | apq8056_firmware | — | cpe:2.3:o:qualcomm:apq8056_firmware:-:*:*:*:*:*:*:* |
| qualcomm | apq8076_firmware | — | cpe:2.3:o:qualcomm:apq8076_firmware:-:*:*:*:*:*:*:* |
| qualcomm | apq8096_firmware | — | cpe:2.3:o:qualcomm:apq8096_firmware:-:*:*:*:*:*:*:* |
| qualcomm | apq8098_firmware | — | cpe:2.3:o:qualcomm:apq8098_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9655_firmware | — | cpe:2.3:o:qualcomm:mdm9655_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8952_firmware | — | cpe:2.3:o:qualcomm:msm8952_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8956_firmware | — | cpe:2.3:o:qualcomm:msm8956_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8976_firmware | — | cpe:2.3:o:qualcomm:msm8976_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8976sg_firmware | — | cpe:2.3:o:qualcomm:msm8976sg_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8996_firmware | — | cpe:2.3:o:qualcomm:msm8996_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8996sg_firmware | — | cpe:2.3:o:qualcomm:msm8996sg_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8998_firmware | — | cpe:2.3:o:qualcomm:msm8998_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm4290_firmware | — | cpe:2.3:o:qualcomm:qcm4290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcm6125_firmware | — | cpe:2.3:o:qualcomm:qcm6125_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs410_firmware | — | cpe:2.3:o:qualcomm:qcs410_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs4290_firmware | — | cpe:2.3:o:qualcomm:qcs4290_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs610_firmware | — | cpe:2.3:o:qualcomm:qcs610_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qcs6125_firmware | — | cpe:2.3:o:qualcomm:qcs6125_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qsm8250_firmware | — | cpe:2.3:o:qualcomm:qsm8250_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6145p_firmware | — | cpe:2.3:o:qualcomm:sa6145p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6150p_firmware | — | cpe:2.3:o:qualcomm:sa6150p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6155_firmware | — | cpe:2.3:o:qualcomm:sa6155_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa6155p_firmware | — | cpe:2.3:o:qualcomm:sa6155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8150p_firmware | — | cpe:2.3:o:qualcomm:sa8150p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8155_firmware | — | cpe:2.3:o:qualcomm:sa8155_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8155p_firmware | — | cpe:2.3:o:qualcomm:sa8155p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sa8195p_firmware | — | cpe:2.3:o:qualcomm:sa8195p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sc7180_firmware | — | cpe:2.3:o:qualcomm:sc7180_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sda640_firmware | — | cpe:2.3:o:qualcomm:sda640_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sda660_firmware | — | cpe:2.3:o:qualcomm:sda660_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sda845_firmware | — | cpe:2.3:o:qualcomm:sda845_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sda855_firmware | — | cpe:2.3:o:qualcomm:sda855_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm640_firmware | — | cpe:2.3:o:qualcomm:sdm640_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm660_firmware | — | cpe:2.3:o:qualcomm:sdm660_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm830_firmware | — | cpe:2.3:o:qualcomm:sdm830_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm845_firmware | — | cpe:2.3:o:qualcomm:sdm845_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm850_firmware | — | cpe:2.3:o:qualcomm:sdm850_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx50m_firmware | — | cpe:2.3:o:qualcomm:sdx50m_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx55_firmware | — | cpe:2.3:o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx55m_firmware | — | cpe:2.3:o:qualcomm:sdx55m_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm4250_firmware | — | cpe:2.3:o:qualcomm:sm4250_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm4250p_firmware | — | cpe:2.3:o:qualcomm:sm4250p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm6115_firmware | — | cpe:2.3:o:qualcomm:sm6115_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm6115p_firmware | — | cpe:2.3:o:qualcomm:sm6115p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm6125_firmware | — | cpe:2.3:o:qualcomm:sm6125_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm6150_firmware | — | cpe:2.3:o:qualcomm:sm6150_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm6150p_firmware | — | cpe:2.3:o:qualcomm:sm6150p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm6250_firmware | — | cpe:2.3:o:qualcomm:sm6250_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm6250p_firmware | — | cpe:2.3:o:qualcomm:sm6250p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm6350_firmware | — | cpe:2.3:o:qualcomm:sm6350_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7125_firmware | — | cpe:2.3:o:qualcomm:sm7125_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7150_firmware | — | cpe:2.3:o:qualcomm:sm7150_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7150p_firmware | — | cpe:2.3:o:qualcomm:sm7150p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7225_firmware | — | cpe:2.3:o:qualcomm:sm7225_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7250_firmware | — | cpe:2.3:o:qualcomm:sm7250_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm7250p_firmware | — | cpe:2.3:o:qualcomm:sm7250p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm8150_firmware | — | cpe:2.3:o:qualcomm:sm8150_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm8150p_firmware | — | cpe:2.3:o:qualcomm:sm8150p_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sm8250_firmware | — | cpe:2.3:o:qualcomm:sm8250_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sxr2130_firmware | — | cpe:2.3:o:qualcomm:sxr2130_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sxr2130p_firmware | — | cpe:2.3:o:qualcomm:sxr2130p_firmware:-:*:*:*:*:*:*:* |
| URL | タグ |
|---|---|
| https://blog.checkpoint.com/2020/08/06/achilles-small-chip-big-peril/ | Third Party Advisory |
| https://research.checkpoint.com/2021/pwn2own-qualcomm-dsp/ | Exploit Third Party Advisory |
| https://www.qualcomm.com/company/product-security/bulletins/november-2020-bulletin | Vendor Advisory |