CVE-2020-3684: High severity Google Android vulnerability
u'QSEE reads the access permission policy for the SMEM TOC partition from the SMEM TOC contents populated by XBL Loader and applies them without validation' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Agatti, APQ8009, APQ8098, Bitra, IPQ6018, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8998, Nicobar, QCA6390, QCS404, QCS405, QCS605, QCS610, Rennell, SA415M, SA515M, SA6155P, SA8155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3684?
CVE-2020-3684 has been classified with a high severity rating due to its potential impact on device security.
How do I fix CVE-2020-3684?
To mitigate CVE-2020-3684, users should apply the latest firmware updates provided by Qualcomm or their device manufacturers.
Which devices are affected by CVE-2020-3684?
CVE-2020-3684 affects various Qualcomm Snapdragon platforms, including Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, and Mobile.
What type of vulnerability is CVE-2020-3684?
CVE-2020-3684 is a vulnerability resulting from insufficient validation of access permissions in the QSEE component.
Is CVE-2020-3684 being exploited in the wild?
As of now, there are no confirmed reports indicating active exploitation of CVE-2020-3684 in the wild.