PT-2020-17688 · Qualcomm · Qcs610+21
Published
2020-11-02
·
Updated
2020-11-06
·
CVE-2020-3692
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Snapdragon Auto versions prior to the fixed version
Snapdragon Compute versions prior to the fixed version
Snapdragon Consumer IOT versions prior to the fixed version
Snapdragon Industrial IOT versions prior to the fixed version
Snapdragon Mobile versions prior to the fixed version
Agatti versions prior to the fixed version
Kamorta versions prior to the fixed version
Nicobar versions prior to the fixed version
QCM6125 versions prior to the fixed version
QCS610 versions prior to the fixed version
Rennell versions prior to the fixed version
SA415M versions prior to the fixed version
Saipan versions prior to the fixed version
SC7180 versions prior to the fixed version
SC8180X versions prior to the fixed version
SDX24 versions prior to the fixed version
SDX55 versions prior to the fixed version
SM6150 versions prior to the fixed version
SM7150 versions prior to the fixed version
SM8150 versions prior to the fixed version
SM8250 versions prior to the fixed version
SXR2130 versions prior to the fixed version
Description
The issue is related to a possible buffer overflow while updating the output buffer for IMEI and Gateway Address due to a lack of input validation for parameters received from the server.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agatti
Kamorta
Nicobar
Qcm6125
Qcs610
Rennell
Sa415M
Sc7180
Sc8180X
Sdx24
Sdx55
Sm6150
Sm7150
Sm8150
Sm8250
Sxr2130
Saipan
Snapdragon Auto
Snapdragon Compute
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile