CVE-2020-3702: Medium severity qualcomm apq8053 vulnerability

Published Sep 8, 2020
·
Updated

Last updated 25 April 2025

Other sources

u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MSM8909W, MSM8996AU, QCA9531, QCN5502, QCS405, SDX20, SM6150, SM7150

Launchpad

Affected Software

61 affected componentsFixes available
All of the following
Qualcomm Apq8053 Firmware
Qualcomm Apq8053
All of the following
Qualcomm Ipq4019 Firmware
Qualcomm IPQ4019
All of the following
Qualcomm Ipq8064 Firmware
Qualcomm IPQ8064
All of the following
Qualcomm Msm8909w Firmware
Qualcomm MSM8909W
All of the following
Qualcomm Msm8996au Firmware
Qualcomm MSM8996AU
All of the following
Qualcomm Qca9531 Firmware
Qualcomm Qca9531
All of the following
Qualcomm Qcn5502 Firmware
Qualcomm Qcn5502
All of the following
Qualcomm Qcs405 Firmware
Qualcomm QCS405
All of the following
Qualcomm Sdx20 Firmware
Qualcomm SDX20
All of the following
Qualcomm Sm6150 Firmware
Qualcomm SM6150
All of the following
Qualcomm Sm7150 Firmware
Qualcomm SM7150
Debian Debian Linux=10.0
All of the following
Arista Access Point<=8.8.3-12
Any of the following
Arista Av2
Arista C-75
Arista C75-e
Arista O-90
Arista O90e
Arista W-68
Debian Debian Linux=9.0
Qualcomm Apq8053 Firmware
Qualcomm Apq8053
Qualcomm Ipq4019 Firmware
Qualcomm IPQ4019
Qualcomm Ipq8064 Firmware
Qualcomm IPQ8064
Qualcomm Msm8909w Firmware
Qualcomm MSM8909W
Qualcomm Msm8996au Firmware
Qualcomm MSM8996AU
Qualcomm Qca9531 Firmware
Qualcomm Qca9531
Qualcomm Qcn5502 Firmware
Qualcomm Qcn5502
Qualcomm Qcs405 Firmware
Qualcomm QCS405
Qualcomm Sdx20 Firmware
Qualcomm SDX20
Qualcomm Sm6150 Firmware
Qualcomm SM6150
Qualcomm Sm7150 Firmware
Qualcomm SM7150
Arista Access Point<=8.8.3-12
Arista Av2
Arista C-75
Arista C75-e
Arista O-90
Arista O90e
Arista W-68
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Sep 8, 2020
CVE Published
via MITRE·09:31 AM
Data Sourced
via MITRE·09:31 AM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:51 PM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·04:24 AM
RemedyDescriptionSeverityAffected Software
May 6, 2025
Data Sourced
via Debian·04:27 AM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-3702?

CVE-2020-3702 has been classified with a significant severity level due to its potential to lead to information disclosure.

2

How do I fix CVE-2020-3702?

To resolve CVE-2020-3702, update to a patched version of the affected firmware or software, as listed in the security advisories.

3

Which devices are affected by CVE-2020-3702?

CVE-2020-3702 affects various Qualcomm chipsets including APQ8053, IPQ4019, IPQ8064, and several others, as well as Arista Wireless Access Points.

4

What type of vulnerability is CVE-2020-3702?

CVE-2020-3702 is a network vulnerability that can cause internal errors in WLAN devices stemming from crafted network traffic.

5

Can CVE-2020-3702 enable unauthorized access to data?

Yes, CVE-2020-3702 can potentially lead to unauthorized information disclosure over the air due to improper layer 2 encryption.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203