PT-2020-17678 · Qualcomm · Snapdragon Connectivity+6

Published

2020-11-02

·

Updated

2020-11-06

·

CVE-2020-3673

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Snapdragon Auto versions Agatti through SM8250 Snapdragon Compute versions Agatti through SM8250 Snapdragon Connectivity versions Agatti through SM8250 Snapdragon Consumer IOT versions Agatti through SM8250 Snapdragon Industrial IOT versions Agatti through SM8250 Snapdragon Mobile versions Agatti through SM8250 Snapdragon Wearables versions Agatti through SM8250
Description A buffer overflow can occur during SIP message packet processing due to a lack of validation for the index length when storing values in an array. This issue affects various Snapdragon products.
Recommendations For Snapdragon Auto, update to a version that includes the fix for this issue. For Snapdragon Compute, update to a version that includes the fix for this issue. For Snapdragon Connectivity, update to a version that includes the fix for this issue. For Snapdragon Consumer IOT, update to a version that includes the fix for this issue. For Snapdragon Industrial IOT, update to a version that includes the fix for this issue. For Snapdragon Mobile, update to a version that includes the fix for this issue. For Snapdragon Wearables, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling SIP message packet processing until a patch is available.

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-3673

Affected Products

Snapdragon Auto
Snapdragon Compute
Snapdragon Connectivity
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Wearables