First published: Mon Oct 05 2020(Updated: )
u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received from server' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Agatti, Kamorta, Nicobar, QCM6125, QCS610, Rennell, SA415M, Saipan, SC7180, SC8180X, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Qualcomm Agatti Firmware | ||
Qualcomm Agatti | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Nicobar | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Rennell Firmware | ||
Google Android | ||
Qualcomm Sa415m Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Sc8180x Firmware | ||
Qualcomm Sc8180x | ||
Qualcomm Sdx24 Firmware | ||
Google Android | ||
Qualcomm Sdx55 Firmware | ||
Qualcomm Sdx55 | ||
Qualcomm Sm6150 Firmware | ||
Qualcomm Sm6150 | ||
Qualcomm Sm7150 Firmware | ||
Qualcomm Sm7150 | ||
Qualcomm Sm8150 Firmware | ||
Qualcomm Sm8150 | ||
Qualcomm Sm8250 Firmware | ||
Qualcomm SM8250 | ||
Qualcomm Sxr2130 Firmware | ||
Qualcomm Sxr2130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3692 is a vulnerability in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, and Snapdragon Mobile that allows for possible buffer overflow during the update of the output buffer for IMEI and Gateway Address.
CVE-2020-3692 affects Google Android and various Qualcomm firmware versions including Agatti, Kamorta, Nicobar, Rennell, Sa415m, Saipan, Sc7180, Sc8180x, Sdx24, Sdx55, Sm6150, Sm7150, Sm8150, and Sm8250.
CVE-2020-3692 has a severity of critical with a CVSS severity score of 9.0.
Apply the latest security updates provided by Qualcomm and Google to fix CVE-2020-3692.
More information about CVE-2020-3692 can be found on the official Android Security Bulletin for October 2020 and Qualcomm's product security bulletin for October 2020.