#VU112428 Improper Validation of Array Index in Qualcomm products - CVE-2020-3632
Published: July 7, 2025
Vulnerability identifier: #VU112428
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-3632
CWE-ID: CWE-129
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
QSM8350
SC7180
SDX55M
SM6250
SM6250P
SM7125
SM7150P
SM7250
SM7250P
SM8150P
SM8350
SM8350P
SXR2130P
SDX55
SM6150
SM7150
SM8150
SM8250
SXR2130
QSM8350
SC7180
SDX55M
SM6250
SM6250P
SM7125
SM7150P
SM7250
SM7250P
SM8150P
SM8350
SM8350P
SXR2130P
SDX55
SM6150
SM7150
SM8150
SM8250
SXR2130
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in MHI Ring Validation. A local application can execute arbitrary code.
Remediation
Install security update from vendor's website.