PT-2020-17688 · Qualcomm · Qcs610+21

Published

2020-11-02

·

Updated

2020-11-06

·

CVE-2020-3692

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Snapdragon Auto versions prior to the fixed version Snapdragon Compute versions prior to the fixed version Snapdragon Consumer IOT versions prior to the fixed version Snapdragon Industrial IOT versions prior to the fixed version Snapdragon Mobile versions prior to the fixed version Agatti versions prior to the fixed version Kamorta versions prior to the fixed version Nicobar versions prior to the fixed version QCM6125 versions prior to the fixed version QCS610 versions prior to the fixed version Rennell versions prior to the fixed version SA415M versions prior to the fixed version Saipan versions prior to the fixed version SC7180 versions prior to the fixed version SC8180X versions prior to the fixed version SDX24 versions prior to the fixed version SDX55 versions prior to the fixed version SM6150 versions prior to the fixed version SM7150 versions prior to the fixed version SM8150 versions prior to the fixed version SM8250 versions prior to the fixed version SXR2130 versions prior to the fixed version
Description The issue is related to a possible buffer overflow while updating the output buffer for IMEI and Gateway Address due to a lack of input validation for parameters received from the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-3692

Affected Products

Agatti
Kamorta
Nicobar
Qcm6125
Qcs610
Rennell
Sa415M
Sc7180
Sc8180X
Sdx24
Sdx55
Sm6150
Sm7150
Sm8150
Sm8250
Sxr2130
Saipan
Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile