Out-of-bounds read in Qualcomm products - CVE-2020-3700
Published: July 10, 2020 / Updated: March 3, 2021
Vulnerability identifier: #VU29647
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3700
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in WIN WLAN Host. A remote attacker can trigger out-of-bounds read error and read contents of memory on the system.
Affected software
SM8150
APQ8096AU
MDM9607
MSM8909W
MSM8996AU
QCA6574AU
SC8180X
SDM439
SDX55
APQ8053
SM8250
SXR2130
IPQ4019
IPQ8064
IPQ8074
QCA9531
QCA9558
QCA9980
Google Android
APQ8096AU
MDM9607
MSM8909W
MSM8996AU
QCA6574AU
SC8180X
SDM439
SDX55
APQ8053
SM8250
SXR2130
IPQ4019
IPQ8064
IPQ8074
QCA9531
QCA9558
QCA9980
Google Android
How to mitigate CVE-2020-3700
Install updates from vendor's website.