CVE-2020-3700 PUBLISHED CVSS 7.5 HIGH

Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi driver with no additional execution privileges needed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8909W, MSM8996AU, QCA6574AU, QCA9531, QCA9558, QCA9980, SC8180X, SDM439, SDX55, SM8150, SM8250, SXR2130

EPSS 0.43% · 62.5th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.43%
62.5th percentile

Affected Products

VendorProductVersions
qualcommmdm9607_firmware
qualcommapq8053_firmware
qualcommqca9531_firmware
qualcommqca9980_firmware
qualcommsdx55_firmware
qualcommsdm439_firmware
qualcommsc8180x_firmware
qualcommipq4019_firmware
qualcommsm8250_firmware
qualcommmsm8996au_firmware
qualcommqca6574au_firmware
qualcommqca9558_firmware
qualcommsxr2130_firmware
qualcommsm8150_firmware
qualcommipq8074_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and NetworkingAPQ8053, APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8909W, MSM8996AU, QCA6574AU, QCA9531, QCA9558, QCA9980, SC8180X, SDM439, SDX55, SM8150, SM8250, SXR2130
qualcommipq8064_firmware
qualcommapq8096au_firmware
qualcommmsm8909w_firmware

Timeline

References

Open in Interactive Console →