PT-2019-5793 · Qualcomm · Qualcomm Rennell+3

Publicado

2019-07-20

·

Atualizado

2021-07-21

·

CVE-2020-3628

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Consumer IOT versions prior to the fixed version Qualcomm Snapdragon Mobile in APQ8053 versions prior to the fixed version Qualcomm Rennell versions prior to the fixed version Qualcomm SDX20 versions prior to the fixed version
Description The issue is related to improper access due to a socket opened by the logging application without specifying the localhost address. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Qualcomm Snapdragon Consumer IOT, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Mobile in APQ8053, update to a version that includes the fix for this issue. For Qualcomm Rennell, update to a version that includes the fix for this issue. For Qualcomm SDX20, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the logging application until a patch is available.

Correção

Improper Access Control

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-02306
CVE-2020-3628

Produtos afetados

Qualcomm Rennell
Qualcomm Sdx20
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Mobile