First published: Mon Jul 06 2020(Updated: )
Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi driver with no additional execution privileges needed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8909W, MSM8996AU, QCA6574AU, QCA9531, QCA9558, QCA9980, SC8180X, SDM439, SDX55, SM8150, SM8250, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
qualcomm apq8053-ac firmware | ||
Qualcomm APQ8053 Firmware | ||
Qualcomm APQ8096AU Firmware | ||
Qualcomm APQ8096AU Firmware | ||
Qualcomm IPQ4019 | ||
Qualcomm IPQ4019 Firmware | ||
Qualcomm IPQ8064 Firmware | ||
Qualcomm IPQ8064 Firmware | ||
Qualcomm IPQ8074 Firmware | ||
Qualcomm IPQ8074A | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
Qualcomm MSM8909W | ||
Qualcomm Snapdragon 8909 | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm QCA6574 Firmware | ||
Qualcomm QCA6574AU | ||
Qualcomm QCA9531 | ||
Qualcomm QCA9531 | ||
Qualcomm QCA9558 | ||
qualcomm qca9558 Firmware | ||
qualcomm qca9980 firmware | ||
Qualcomm QCA9980 | ||
qualcomm SC8180X firmware | ||
Qualcomm SC8180X | ||
qualcomm SDM439 firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SDX55M Firmware | ||
Qualcomm SDX55 Firmware | ||
Qualcomm SM8150P Firmware | ||
Qualcomm SM8150 Fusion | ||
Qualcomm SM8250 | ||
Qualcomm qsm8250 | ||
qualcomm SXR2130P firmware | ||
Qualcomm SXR2130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3700 is a vulnerability that could lead to local information disclosure in the wifi driver of various Qualcomm products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & M, and several others.
CVE-2020-3700 has a severity rating of 7.5 out of 10, which is classified as high.
CVE-2020-3700 affects Qualcomm products such as APQ8053 Firmware, APQ8096AU Firmware, Ipq4019 Firmware, Ipq8064 Firmware, Ipq8074 Firmware, Mdm9607 Firmware, Msm8909w Firmware, Msm8996au Firmware, Qca6574au Firmware, Qca9531 Firmware, Qca9558 Firmware, Qca9980 Firmware, Sc8180x Firmware, Sdm439 Firmware, Sdx55 Firmware, Sm8150 Firmware, Sm8250 Firmware, and Sxr2130 Firmware, as well as Google Android.
To fix CVE-2020-3700, it is recommended to apply the patches provided by Qualcomm. Please refer to the official Qualcomm security bulletins for more information.
You can find more information about CVE-2020-3700 in the official Qualcomm security bulletins and the associated commit on the Code Aurora website.