Improper Validation of Array Index in Qualcomm products - CVE-2020-3639
Published: July 7, 2025
Vulnerability identifier: #VU112415
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3639
CWE-ID: CWE-129
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in Modem Data. A remote attacker can execute arbitrary code.
Affected software
SDM632
SDX55
SDX24
SDM845
SDM710
SDM670
SDM660
SDM636
SDM630
SDM450
SDM439
SDM429W
SDM429
SDA845
SXR1130
SM8150
SM7150
SDA660
SM6150
MSM8996AU
MSM8953
MSM8940
MSM8937
MSM8920
MSM8917
MSM8905
MDM9650
MDM9640
MDM9607
APQ8053
APQ8017
SA6155P
SC8180X
APQ8009
QM215
QCS605
SDX50M
SDM850
SDM712
SDM640
SDX55M
SDM455
SDM1000
SDA855
SDA670
SM7125
SXR1120
SM8350P
SM8350
SM8150P
SM7250P
SM7250
SM7150P
SM6250P
SM6250
SM6150P
SM6125
SM6115P
SM6115
SM4250P
SM4250
SM4125
MSM8209
QCM6125
QCM4290
MSM8909
MSM8608
QCS410
MSM8208
MSM8108
MDM9628
MDM9250
APQ8037
SDA640
SDA429W
SC8180XP
SC8180X+SDX55
SC7180
SA8195P
SA8155P
SA8155
SA8150P
SA6150P
SA6145P
SA415M
QSM8350
QCS6125
QCS610
QCS603
QCS4290
SDX55
SDX24
SDM845
SDM710
SDM670
SDM660
SDM636
SDM630
SDM450
SDM439
SDM429W
SDM429
SDA845
SXR1130
SM8150
SM7150
SDA660
SM6150
MSM8996AU
MSM8953
MSM8940
MSM8937
MSM8920
MSM8917
MSM8905
MDM9650
MDM9640
MDM9607
APQ8053
APQ8017
SA6155P
SC8180X
APQ8009
QM215
QCS605
SDX50M
SDM850
SDM712
SDM640
SDX55M
SDM455
SDM1000
SDA855
SDA670
SM7125
SXR1120
SM8350P
SM8350
SM8150P
SM7250P
SM7250
SM7150P
SM6250P
SM6250
SM6150P
SM6125
SM6115P
SM6115
SM4250P
SM4250
SM4125
MSM8209
QCM6125
QCM4290
MSM8909
MSM8608
QCS410
MSM8208
MSM8108
MDM9628
MDM9250
APQ8037
SDA640
SDA429W
SC8180XP
SC8180X+SDX55
SC7180
SA8195P
SA8155P
SA8155
SA8150P
SA6150P
SA6145P
SA415M
QSM8350
QCS6125
QCS610
QCS603
QCS4290
How to mitigate CVE-2020-3639
Install security update from vendor's website.