First published: Mon May 04 2020(Updated: )
Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | ||
Qualcomm Ipq6018 | ||
Qualcomm Ipq8074 Firmware | ||
Qualcomm Ipq8074 | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Nicobar | ||
Qualcomm Qca6390 Firmware | ||
Qualcomm Qca6390 | ||
Qualcomm Qca8081 Firmware | ||
Google Android | ||
Qualcomm Qcs404 Firmware | ||
Google Android | ||
Qualcomm Qcs405 Firmware | ||
Qualcomm Qcs405 | ||
Qualcomm Rennell Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Sc8180x Firmware | ||
Qualcomm Sc8180x | ||
Qualcomm Sda845 Firmware | ||
Qualcomm Sda845 | ||
Qualcomm Sdm670 Firmware | ||
Qualcomm Sdm670 | ||
Qualcomm Sdm710 Firmware | ||
Qualcomm Sdm710 | ||
Qualcomm Sdm850 Firmware | ||
Qualcomm Sdm850 | ||
Qualcomm Sm6150 Firmware | ||
Qualcomm Sm6150 | ||
Qualcomm Sm7150 Firmware | ||
Qualcomm Sm7150 | ||
Qualcomm Sm8150 Firmware | ||
Qualcomm Sm8150 | ||
Qualcomm Sxr1130 Firmware | ||
Qualcomm Sxr1130 | ||
Qualcomm Sxr2130 Firmware | ||
Qualcomm Sxr2130 | ||
Google Android | ||
Google Android | ||
Qualcomm Qcs605 Firmware | ||
Google Android | ||
Qualcomm Sdm845 Firmware | ||
Qualcomm Sdm845 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3645 is a vulnerability in Snapdragon processors that can cause the firmware to crash if the encrypted data length in FILS IE of a reassoc response is more than 528 bytes.
The affected software includes Google Android and various Qualcomm firmware versions such as IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCS404, QCS405, Rennell, SC7180, SC8180x, SDA845, SDM670, SDM710, SDM850, SM6150, SM7150, SM8150, SXR1130, SXR2130, QCN7605, QCS605, and SDM845.
CVE-2020-3645 has a severity rating of high, with a CVSS score of 7.5.
To fix CVE-2020-3645, users are advised to apply the necessary firmware updates provided by Qualcomm and follow the recommendations outlined in the Qualcomm security bulletin.
More information about CVE-2020-3645 can be found in the Qualcomm security bulletin and the Android security bulletin for May 2020.