PT-2020-17661 · Qualcomm+1 · Snapdragon Connectivity+7

Published

2020-04-16

·

Updated

2021-07-21

·

CVE-2020-3653

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon versions (affected versions not specified)
Description The issue is related to a possible buffer over-read in the Windows WLAN driver function. This occurs due to the lack of a check on the length of a variable received from userspace in certain Qualcomm Snapdragon components, including Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, and SDM850.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-3653

Affected Products

Msm8998
Qca6390
Sc7180
Sc8180X
Sdm850
Snapdragon Compute
Snapdragon Connectivity
Windows