PT-2020-17661 · Qualcomm+1 · Snapdragon Connectivity+7
Published
2020-04-16
·
Updated
2021-07-21
·
CVE-2020-3653
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Qualcomm Snapdragon versions (affected versions not specified)
Description
The issue is related to a possible buffer over-read in the Windows WLAN driver function. This occurs due to the lack of a check on the length of a variable received from userspace in certain Qualcomm Snapdragon components, including Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, and SDM850.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Out of bounds Read
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Msm8998
Qca6390
Sc7180
Sc8180X
Sdm850
Snapdragon Compute
Snapdragon Connectivity
Windows