First published: Mon Aug 03 2020(Updated: )
u'Buffer Overflow in mic calculation for WPA due to copying data into buffer without validating the length of buffer' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8098, IPQ5018, IPQ6018, IPQ8074, Kamorta, MSM8998, Nicobar, QCA6390, QCA8081, QCS404, QCS405, QCS605, Rennell, SA415M, Saipan, SC7180, SC8180X, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SM8250, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Qualcomm Apq8098 | ||
Qualcomm Ipq5018 Firmware | ||
Qualcomm Ipq5018 | ||
Google Android | ||
Qualcomm Ipq6018 | ||
Qualcomm Ipq8074 Firmware | ||
Qualcomm Ipq8074 | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm MSM8998 | ||
Google Android | ||
Qualcomm Nicobar | ||
Qualcomm Qca6390 Firmware | ||
Qualcomm Qca6390 | ||
Qualcomm Qca8081 Firmware | ||
Google Android | ||
Qualcomm Qcs404 Firmware | ||
Google Android | ||
Qualcomm Qcs405 Firmware | ||
Qualcomm Qcs405 | ||
Qualcomm Qcs605 Firmware | ||
Google Android | ||
Qualcomm Rennell Firmware | ||
Google Android | ||
Qualcomm Sa415m Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Sc8180x Firmware | ||
Qualcomm Sc8180x | ||
Qualcomm Sda845 Firmware | ||
Qualcomm Sda845 | ||
Qualcomm Sdm630 Firmware | ||
Qualcomm Sdm630 | ||
Google Android | ||
Qualcomm Sdm636 | ||
Qualcomm Sdm660 Firmware | ||
Qualcomm Sdm660 | ||
Qualcomm Sdm670 Firmware | ||
Qualcomm Sdm670 | ||
Qualcomm Sdm710 Firmware | ||
Qualcomm Sdm710 | ||
Qualcomm Sdm845 Firmware | ||
Qualcomm Sdm845 | ||
Qualcomm Sdm850 Firmware | ||
Qualcomm Sdm850 | ||
Qualcomm Sm6150 Firmware | ||
Qualcomm Sm6150 | ||
Qualcomm Sm7150 Firmware | ||
Qualcomm Sm7150 | ||
Qualcomm Sm8150 Firmware | ||
Qualcomm Sm8150 | ||
Qualcomm Sm8250 Firmware | ||
Qualcomm SM8250 | ||
Qualcomm Sxr1130 Firmware | ||
Qualcomm Sxr1130 | ||
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Vulnerability CVE-2020-3667 is a buffer overflow vulnerability in mic calculation for WPA due to copying data into buffer without validating the length of buffer.
The severity of vulnerability CVE-2020-3667 is critical with a CVSS score of 9.8.
The vulnerability affects Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Inf. The software products include Google Android, Qualcomm Apq8098, Qualcomm Ipq5018 Firmware, Qualcomm Ipq5018, Qualcomm Ipq6018 Firmware, Qualcomm Ipq6018, Qualcomm Ipq8074 Firmware, Qualcomm Ipq8074, Qualcomm Kamorta Firmware, Qualcomm MSM8998, Qualcomm Nicobar, Qualcomm Qca6390 Firmware, Qualcomm Qca6390, Qualcomm Qca8081 Firmware, Qualcomm Qca8081, Qualcomm Qcs404 Firmware, Qualcomm Qcs404, Qualcomm Qcs405 Firmware, Qualcomm Qcs405, Qualcomm Qcs605 Firmware, Qualcomm Qcs605, Qualcomm Rennell Firmware, Qualcomm Sa415m Firmware, Qualcomm Sa415m, Qualcomm Saipan Firmware, Qualcomm Sc7180, Qualcomm Sc7180x Firmware, Qualcomm Sc8180x, Qualcomm Sda845 Firmware, Qualcomm Sda845, Qualcomm Sdm630 Firmware, Qualcomm Sdm630, Qualcomm Sdm636, Qualcomm Sdm660 Firmware, Qualcomm Sdm660, Qualcomm Sdm670 Firmware, Qualcomm Sdm670, Qualcomm Sdm710 Firmware, Qualcomm Sdm710, Qualcomm Sdm845 Firmware, Qualcomm Sdm845, Qualcomm Sdm850 Firmware, Qualcomm Sdm850, Qualcomm Sm6150, Qualcomm Sm7150, Qualcomm Sm8150 Firmware, Qualcomm Sm8150, Qualcomm Sm8250 Firmware, Qualcomm SM8250, Qualcomm Sxr1130 Firmware, Qualcomm Sxr1130.
More information about vulnerability CVE-2020-3667 can be found at the following references: [Qualcomm Security Bulletin](https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin), [Android Security Bulletin](https://source.android.com/docs/security/bulletin/2020-08-01/#asterisk)
The Common Weakness Enumeration (CWE) for vulnerability CVE-2020-3667 includes CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-120 (Buffer Copy without Checking Size of Input).