CVE-2020-3673: Out-of-bounds Read
u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check to validate the index length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in Agatti, APQ8053, APQ8096AU, APQ8098, Bitra, Kamorta, MSM8905, MSM8909W, MSM8917, MSM8940, MSM8953, MSM8996AU, Nicobar, QCA6390, QCA6574AU, QCM2150, QCS605, QM215, Rennell, SA6155P, SA8155P, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3673?
CVE-2020-3673 is classified as a high severity vulnerability due to the potential for excessive resource consumption or application crash.
How do I fix CVE-2020-3673?
To fix CVE-2020-3673, users should update their affected Qualcomm Snapdragon firmware to the latest available version provided by the vendor.
Which devices are affected by CVE-2020-3673?
CVE-2020-3673 affects various devices running Qualcomm's Snapdragon firmware, including those in automotive, mobile, and IoT applications.
What type of vulnerability is CVE-2020-3673?
CVE-2020-3673 is a buffer overflow vulnerability that can occur during the SIP message packet processing.
Is CVE-2020-3673 exploitable remotely?
Yes, CVE-2020-3673 may be remotely exploitable if the vulnerable Snapdragon firmware processes specially crafted SIP messages.