Buffer overflow in Qualcomm products - CVE-2020-3667

 

Buffer overflow in Qualcomm products - CVE-2020-3667

Published: May 17, 2025


Vulnerability identifier: #VU109315
CSH Severity:
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:/VI:/VA:/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3667
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows #AV# #AU# to #BASIC_IMPACT#.

The vulnerability exists due to improper input validation in WLAN. #AV# #AU# can #EXT_IMPACT#.


Affected software

SC7180
SDM850
SA415M
QCS404
QCA8081
QCA6390
IPQ6018
IPQ5018
SXR1130
SM8250
SM8150
SM7150
SM6150
SDM845
SDM710
SDM670
SDM660
SDM636
SDM630
SDA845
SC8180X
APQ8098
Saipan
Rennell
QCS605
QCS405
Nicobar
MSM8998
Kamorta
IPQ8074

How to mitigate CVE-2020-3667

Install security update from vendor's website.


External References

Related Security Bulletins