CVE-2020-3704: Input Validation
u'While processing invalid connection request PDU which is nonstandard (interval or timeout is 0) from central device may lead peripheral system enter into dead lock state.(This CVE is equivalent to InvalidConnectionRequest(CVE-2019-19193) mentioned in sweyntooth paper)' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Agatti, APQ8009, APQ8017, APQ8053, AR9344, Bitra, IPQ5018, Kamorta, MDM9607, MDM9640, MDM9650, MSM8996AU, Nicobar, QCA6174A, QCA6390, QCA6574AU, QCA9377, QCA9886, QCM6125, QCN7605, QCS404, QCS405, QCS605, QCS610, QRB5165, Rennell, SA415M, SA515M, Saipan, SC7180, SC8180X, SDA845, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3704?
CVE-2020-3704 is classified as a moderate severity vulnerability due to its potential to cause a deadlock state in affected systems.
How do I fix CVE-2020-3704?
To mitigate CVE-2020-3704, users should apply available updates and patches from their device manufacturers.
Which devices are affected by CVE-2020-3704?
CVE-2020-3704 affects various Qualcomm platforms including certain Android devices with Snapdragon processors.
What is the impact of CVE-2020-3704 on my device?
CVE-2020-3704 can cause affected devices to enter a deadlock state, potentially leading to service disruption.
Is there a workaround for CVE-2020-3704?
Currently, the recommended solution for CVE-2020-3704 is to apply security patches as there are no specific workarounds.