PT-2019-5793 · Qualcomm · Qualcomm Rennell+3
Published
2019-07-20
·
Updated
2021-07-21
·
CVE-2020-3628
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Qualcomm Snapdragon Consumer IOT versions prior to the fixed version
Qualcomm Snapdragon Mobile in APQ8053 versions prior to the fixed version
Qualcomm Rennell versions prior to the fixed version
Qualcomm SDX20 versions prior to the fixed version
Description
The issue is related to improper access due to a socket opened by the logging application without specifying the localhost address. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations
For Qualcomm Snapdragon Consumer IOT, update to a version that includes the fix for this issue.
For Qualcomm Snapdragon Mobile in APQ8053, update to a version that includes the fix for this issue.
For Qualcomm Rennell, update to a version that includes the fix for this issue.
For Qualcomm SDX20, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the logging application until a patch is available.
Fix
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qualcomm Rennell
Qualcomm Sdx20
Qualcomm Snapdragon Consumer Iot
Qualcomm Snapdragon Mobile