Lucene search

K
nvd[email protected]NVD:CVE-2020-3692
HistoryNov 02, 2020 - 7:15 a.m.

CVE-2020-3692

2020-11-0207:15:14
CWE-120
web.nvd.nist.gov
5
buffer overflow
snapdragon
input validation
cve-2020-3692
imei
gateway address

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

71.2%

u’Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received from server’ in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Agatti, Kamorta, Nicobar, QCM6125, QCS610, Rennell, SA415M, Saipan, SC7180, SC8180X, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

Affected configurations

Nvd
Node
qualcommagattiMatch-
AND
qualcommagatti_firmwareMatch-
Node
qualcommkamortaMatch-
AND
qualcommkamorta_firmwareMatch-
Node
qualcommnicobarMatch-
AND
qualcommnicobar_firmwareMatch-
Node
qualcommqcm6125Match-
AND
qualcommqcm6125_firmwareMatch-
Node
qualcommqcs610Match-
AND
qualcommqcs610_firmwareMatch-
Node
qualcommrennellMatch-
AND
qualcommrennell_firmwareMatch-
Node
qualcommsa415mMatch-
AND
qualcommsa415m_firmwareMatch-
Node
qualcommsaipanMatch-
AND
qualcommsaipan_firmwareMatch-
Node
qualcommsc7180_firmwareMatch-
AND
qualcommsc7180Match-
Node
qualcommsc8180x_firmwareMatch-
AND
qualcommsc8180xMatch-
Node
qualcommsdx24_firmwareMatch-
AND
qualcommsdx24Match-
Node
qualcommsdx55_firmwareMatch-
AND
qualcommsdx55Match-
Node
qualcommsm6150_firmwareMatch-
AND
qualcommsm6150Match-
Node
qualcommsm7150_firmwareMatch-
AND
qualcommsm7150Match-
Node
qualcommsm8150_firmwareMatch-
AND
qualcommsm8150Match-
Node
qualcommsm8250_firmwareMatch-
AND
qualcommsm8250Match-
Node
qualcommsxr2130_firmwareMatch-
AND
qualcommsxr2130Match-
VendorProductVersionCPE
qualcommagatti-cpe:2.3:h:qualcomm:agatti:-:*:*:*:*:*:*:*
qualcommagatti_firmware-cpe:2.3:o:qualcomm:agatti_firmware:-:*:*:*:*:*:*:*
qualcommkamorta-cpe:2.3:h:qualcomm:kamorta:-:*:*:*:*:*:*:*
qualcommkamorta_firmware-cpe:2.3:o:qualcomm:kamorta_firmware:-:*:*:*:*:*:*:*
qualcommnicobar-cpe:2.3:h:qualcomm:nicobar:-:*:*:*:*:*:*:*
qualcommnicobar_firmware-cpe:2.3:o:qualcomm:nicobar_firmware:-:*:*:*:*:*:*:*
qualcommqcm6125-cpe:2.3:h:qualcomm:qcm6125:-:*:*:*:*:*:*:*
qualcommqcm6125_firmware-cpe:2.3:o:qualcomm:qcm6125_firmware:-:*:*:*:*:*:*:*
qualcommqcs610-cpe:2.3:h:qualcomm:qcs610:-:*:*:*:*:*:*:*
qualcommqcs610_firmware-cpe:2.3:o:qualcomm:qcs610_firmware:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 341

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

71.2%

Related for NVD:CVE-2020-3692