PT-2019-5793 · Qualcomm · Qualcomm Rennell+3

Published

2019-07-20

·

Updated

2021-07-21

·

CVE-2020-3628

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Consumer IOT versions prior to the fixed version Qualcomm Snapdragon Mobile in APQ8053 versions prior to the fixed version Qualcomm Rennell versions prior to the fixed version Qualcomm SDX20 versions prior to the fixed version
Description The issue is related to improper access due to a socket opened by the logging application without specifying the localhost address. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Qualcomm Snapdragon Consumer IOT, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Mobile in APQ8053, update to a version that includes the fix for this issue. For Qualcomm Rennell, update to a version that includes the fix for this issue. For Qualcomm SDX20, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the logging application until a patch is available.

Fix

Improper Access Control

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02306
CVE-2020-3628

Affected Products

Qualcomm Rennell
Qualcomm Sdx20
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Mobile