CVE-2020-3700: High severity Google Android vulnerability
Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi driver with no additional execution privileges needed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8909W, MSM8996AU, QCA6574AU, QCA9531, QCA9558, QCA9980, SC8180X, SDM439, SDX55, SM8150, SM8250, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-3700?
CVE-2020-3700 is a vulnerability that could lead to local information disclosure in the wifi driver of various Qualcomm products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & M, and several others.
How severe is CVE-2020-3700?
CVE-2020-3700 has a severity rating of 7.5 out of 10, which is classified as high.
Which software is affected by CVE-2020-3700?
CVE-2020-3700 affects Qualcomm products such as APQ8053 Firmware, APQ8096AU Firmware, Ipq4019 Firmware, Ipq8064 Firmware, Ipq8074 Firmware, Mdm9607 Firmware, Msm8909w Firmware, Msm8996au Firmware, Qca6574au Firmware, Qca9531 Firmware, Qca9558 Firmware, Qca9980 Firmware, Sc8180x Firmware, Sdm439 Firmware, Sdx55 Firmware, Sm8150 Firmware, Sm8250 Firmware, and Sxr2130 Firmware, as well as Google Android.
How can I fix CVE-2020-3700?
To fix CVE-2020-3700, it is recommended to apply the patches provided by Qualcomm. Please refer to the official Qualcomm security bulletins for more information.
Where can I find more information about CVE-2020-3700?
You can find more information about CVE-2020-3700 in the official Qualcomm security bulletins and the associated commit on the Code Aurora website.