Buffer overflow in Qualcomm products - CVE-2020-3668
Published: May 17, 2025
Vulnerability identifier: #VU109345
CSH Severity:
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:/VI:/VA:/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3668
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows #AV# #AU# to #BASIC_IMPACT#.
The vulnerability exists due to improper input validation in WLAN. #AV# #AU# can #EXT_IMPACT#.
Affected software
SA415M
SDM850
SC7180
IPQ6018
QCS404
QCA8081
QCA6390
SXR1130
SM8150
SM7150
SM6150
SDM845
SDM710
SDM670
SDA845
SC8180X
Rennell
QCS605
QCS405
QCN7605
Nicobar
Kamorta
IPQ8074
SDM850
SC7180
IPQ6018
QCS404
QCA8081
QCA6390
SXR1130
SM8150
SM7150
SM6150
SDM845
SDM710
SDM670
SDA845
SC8180X
Rennell
QCS605
QCS405
QCN7605
Nicobar
Kamorta
IPQ8074
How to mitigate CVE-2020-3668
Install security update from vendor's website.