First published: Tue Sep 08 2020(Updated: )
u'Buffer over-read Issue in Q6 testbus framework due to diag packet length is not completely validated before accessing the field and leads to Information disclosure.' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Kamorta, Nicobar, QCS605, QCS610, Rennell, SC7180, SDA660, SDM630, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Nicobar | ||
Qualcomm Qcs605 Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Rennell Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Sdm630 Firmware | ||
Qualcomm Sdm630 | ||
Google Android | ||
Qualcomm Sdm636 | ||
Qualcomm Sdm660 Firmware | ||
Qualcomm Sdm660 | ||
Qualcomm Sdm670 Firmware | ||
Qualcomm Sdm670 | ||
Qualcomm Sdm710 Firmware | ||
Qualcomm Sdm710 | ||
Qualcomm Sm6150 Firmware | ||
Qualcomm Sm6150 | ||
Qualcomm Sm7150 Firmware | ||
Qualcomm Sm7150 | ||
Qualcomm Sm8150 Firmware | ||
Qualcomm Sm8150 | ||
Qualcomm Sxr1130 Firmware | ||
Qualcomm Sxr1130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3617 is a buffer over-read vulnerability in the Q6 testbus framework that can lead to information disclosure.
Google Android, Qualcomm Kamorta Firmware, Qualcomm Nicobar Firmware, Qualcomm Qcs605 Firmware, Qualcomm Qcs610 Firmware, Qualcomm Rennell Firmware, Qualcomm Sc7180 Firmware, Qualcomm Sda660 Firmware, Qualcomm Sdm630 Firmware, Qualcomm Sdm636 Firmware, Qualcomm Sdm660 Firmware, Qualcomm Sdm670 Firmware, Qualcomm Sdm710 Firmware, Qualcomm Sm6150 Firmware, Qualcomm Sm7150 Firmware, Qualcomm Sm8150 Firmware, Qualcomm Sxr1130 Firmware.
The severity of CVE-2020-3617 is high with a CVSS score of 7.1.
Update to the latest version of the affected software, as provided by the vendor.
More information about CVE-2020-3617 can be found on the Qualcomm Product Security Bulletins and Android Security Bulletins for September 2020.