PT-2020-17567 · Qualcomm · Snapdragon Industrial Iot+5

Published

2020-06-02

·

Updated

2020-06-03

·

CVE-2020-3615

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Snapdragon Auto versions APQ8009 through SDX55 Snapdragon Compute versions APQ8009 through SDX55 Snapdragon Consumer Electronics Connectivity versions APQ8009 through SDX55 Snapdragon Consumer IOT versions APQ8009 through SDX55 Snapdragon Industrial IOT versions APQ8009 through SDX55 Snapdragon Mobile versions APQ8009 through SDX55
Description The issue arises when valid deauth/disassoc frames are dropped due to improper enum values used to check the frame subtype, specifically when RMF is enabled and a rogue peer sends rogue deauth/disassoc frames. This affects various Snapdragon products.
Recommendations For Snapdragon Auto, update the firmware to properly handle enum values for frame subtype checking. For Snapdragon Compute, update the firmware to properly handle enum values for frame subtype checking. For Snapdragon Consumer Electronics Connectivity, update the firmware to properly handle enum values for frame subtype checking. For Snapdragon Consumer IOT, update the firmware to properly handle enum values for frame subtype checking. For Snapdragon Industrial IOT, update the firmware to properly handle enum values for frame subtype checking. For Snapdragon Mobile, update the firmware to properly handle enum values for frame subtype checking. As a temporary workaround, consider disabling RMF until a patch is available. Restrict access to rogue peers to minimize the risk of exploitation.

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-3615

Affected Products

Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Electronics Connectivity
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile