Improper Validation of Array Index in Qualcomm products - CVE-2020-3632

 

Improper Validation of Array Index in Qualcomm products - CVE-2020-3632

Published: July 7, 2025


Vulnerability identifier: #VU112428
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3632
CWE-ID: CWE-129
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation in MHI Ring Validation. A local application can execute arbitrary code.


Affected software

SM7150P
SXR2130P
SM8350P
SM8350
SM8150P
SM7250P
SM7250
QSM8350
SM7125
SM6250P
SM6250
SDX55M
SC7180
SXR2130
SM8250
SM8150
SM7150
SM6150
SDX55

How to mitigate CVE-2020-3632

Install security update from vendor's website.


External References

Related Security Bulletins