First published: Mon Nov 02 2020(Updated: )
u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8098, Bitra, MSM8909W, MSM8996AU, Nicobar, QCM2150, QCS605, Saipan, SDM429W, SDX20, SM6150, SM8150, SM8250, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Apq8009 Firmware | ||
Qualcomm Apq8009 | ||
Qualcomm Apq8017 Firmware | ||
Qualcomm Apq8017 | ||
Qualcomm Apq8053 Firmware | ||
Qualcomm Apq8053 | ||
Qualcomm Apq8098 Firmware | ||
Qualcomm Apq8098 | ||
Qualcomm Bitra Firmware | ||
Qualcomm Bitra | ||
Qualcomm Msm8909w Firmware | ||
Qualcomm Msm8909w | ||
Qualcomm Msm8996au Firmware | ||
Qualcomm Msm8996au | ||
Qualcomm Nicobar Firmware | ||
Qualcomm Nicobar | ||
Qualcomm Qcm2150 Firmware | ||
Qualcomm Qcm2150 | ||
Qualcomm Qcs605 Firmware | ||
Qualcomm Qcs605 | ||
Qualcomm Saipan Firmware | ||
Qualcomm Saipan | ||
Qualcomm Sdm429w Firmware | ||
Qualcomm Sdm429w | ||
Qualcomm Sdx20 Firmware | ||
Qualcomm Sdx20 | ||
Qualcomm Sm6150 Firmware | ||
Qualcomm Sm6150 | ||
Qualcomm Sm8150 Firmware | ||
Qualcomm Sm8150 | ||
Qualcomm Sm8250 Firmware | ||
Qualcomm SM8250 | ||
Qualcomm Sxr2130 Firmware | ||
Qualcomm Sxr2130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-3693 is high with a score of 7.8.
Devices in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables with specific firmware versions are affected.
CVE-2020-3693 can be exploited by triggering a use out of range pointer issue during the execution of qseecom.
Qualcomm Apq8009, Qualcomm Apq8017, and Qualcomm Apq8053 are affected by CVE-2020-3693.
You can find more information about CVE-2020-3693 on the Qualcomm Product Security Bulletins for October 2020.