← Volver a CVEs
CVE-2020-3700
HIGH7.5
Descripcion
Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi driver with no additional execution privileges needed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8909W, MSM8996AU, QCA6574AU, QCA9531, QCA9558, QCA9980, SC8180X, SDM439, SDX55, SM8150, SM8250, SXR2130
Detalles CVE
Puntuacion CVSS v3.17.5
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado7/30/2020
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
qualcomm:apq8053qualcomm:apq8053_firmwarequalcomm:apq8096auqualcomm:apq8096au_firmwarequalcomm:ipq4019qualcomm:ipq4019_firmwarequalcomm:ipq8064qualcomm:ipq8064_firmwarequalcomm:ipq8074qualcomm:ipq8074_firmwarequalcomm:mdm9607qualcomm:mdm9607_firmwarequalcomm:msm8909wqualcomm:msm8909w_firmwarequalcomm:msm8996auqualcomm:msm8996au_firmwarequalcomm:qca6574auqualcomm:qca6574au_firmwarequalcomm:qca9531qualcomm:qca9531_firmwarequalcomm:qca9558qualcomm:qca9558_firmwarequalcomm:qca9980qualcomm:qca9980_firmwarequalcomm:sc8180xqualcomm:sc8180x_firmwarequalcomm:sdm439qualcomm:sdm439_firmwarequalcomm:sdx55qualcomm:sdx55_firmwarequalcomm:sm8150qualcomm:sm8150_firmwarequalcomm:sm8250qualcomm:sm8250_firmwarequalcomm:sxr2130qualcomm:sxr2130_firmware
Debilidades (CWE)
CWE-125
Referencias
https://www.qualcomm.com/company/product-security/bulletins/july-2020-bulletin(product-security@qualcomm.com)
https://www.qualcomm.com/company/product-security/bulletins/july-2020-security-bulletin(nvd@nist.gov)
https://www.qualcomm.com/company/product-security/bulletins/july-2020-bulletin(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.