Out-of-bounds read in Qualcomm products - CVE-2020-3700
Published: July 10, 2020 / Updated: March 3, 2021
Vulnerability identifier: #VU29647
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-3700
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
APQ8053
QCA9980
QCA9558
QCA9531
IPQ8074
IPQ8064
IPQ4019
SXR2130
SM8250
SM8150
SDX55
SDM439
SC8180X
QCA6574AU
MSM8996AU
MSM8909W
MDM9607
APQ8096AU
APQ8053
QCA9980
QCA9558
QCA9531
IPQ8074
IPQ8064
IPQ4019
SXR2130
SM8250
SM8150
SDX55
SDM439
SC8180X
QCA6574AU
MSM8996AU
MSM8909W
MDM9607
APQ8096AU
Software vendor:
Qualcomm
Qualcomm
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in WIN WLAN Host. A remote attacker can trigger out-of-bounds read error and read contents of memory on the system.
Remediation
Install updates from vendor's website.