First published: Mon Oct 05 2020(Updated: )
u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received from server' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Agatti, Kamorta, Nicobar, QCM6125, QCS610, Rennell, SA415M, Saipan, SC7180, SC8180X, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm Agatti Firmware | ||
Qualcomm Agatti Firmware | ||
Qualcomm Kamorta | ||
qualcomm Kamorta firmware | ||
Qualcomm Nicobar | ||
Qualcomm Nicobar | ||
Qualcomm QCM6125 Firmware | ||
Qualcomm QCM6125 Firmware | ||
Qualcomm QCS610 Firmware | ||
Qualcomm QCS610 Firmware | ||
Qualcomm Rennell Firmware | ||
Qualcomm Rennell Firmware | ||
Qualcomm SA415M Firmware | ||
Qualcomm SA415M Firmware | ||
Qualcomm Saipan Firmware | ||
Qualcomm Saipan Firmware | ||
Qualcomm SC7180P Firmware | ||
Qualcomm SC7180P Firmware | ||
qualcomm SC8180X firmware | ||
Qualcomm SC8180X | ||
Qualcomm SDX24 | ||
Qualcomm SDX24 | ||
Qualcomm SDX55M Firmware | ||
Qualcomm SDX55 Firmware | ||
Qualcomm SM6150P firmware | ||
Qualcomm SM6150P | ||
qualcomm SM7150P firmware | ||
qualcomm SM7150 firmware | ||
Qualcomm SM8150P Firmware | ||
Qualcomm SM8150 Fusion | ||
Qualcomm SM8250 | ||
qualcomm SM8250 firmware | ||
Qualcomm SXR2130P Firmware | ||
Qualcomm SXR2130 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3692 is a vulnerability in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, and Snapdragon Mobile that allows for possible buffer overflow during the update of the output buffer for IMEI and Gateway Address.
CVE-2020-3692 affects Google Android and various Qualcomm firmware versions including Agatti, Kamorta, Nicobar, Rennell, Sa415m, Saipan, Sc7180, Sc8180x, Sdx24, Sdx55, Sm6150, Sm7150, Sm8150, and Sm8250.
CVE-2020-3692 has a severity of critical with a CVSS severity score of 9.0.
Apply the latest security updates provided by Qualcomm and Google to fix CVE-2020-3692.
More information about CVE-2020-3692 can be found on the official Android Security Bulletin for October 2020 and Qualcomm's product security bulletin for October 2020.