7.8

CVE-2020-3629

u'Stack out of bound issue occurs when making query to DSP capabilities due to wrong assumption was made on determining the buffer size for the DSP attributes' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Bitra, Kamorta, Rennell, SC7180, SDM845, SM6150, SM7150, SM8150, SM8250, SXR2130
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Bitra Firmware Version -
   Qualcomm ≫ Bitra Version -
Qualcomm ≫ Kamorta Firmware Version -
   Qualcomm ≫ Kamorta Version -
Qualcomm ≫ Rennell Firmware Version -
   Qualcomm ≫ Rennell Version -
Qualcomm ≫ Sc7180 Firmware Version -
   Qualcomm ≫ Sc7180 Version -
Qualcomm ≫ Sdm845 Firmware Version -
   Qualcomm ≫ Sdm845 Version -
Qualcomm ≫ Sm6150 Firmware Version -
   Qualcomm ≫ Sm6150 Version -
Qualcomm ≫ Sm7150 Firmware Version -
   Qualcomm ≫ Sm7150 Version -
Qualcomm ≫ Sm8150 Firmware Version -
   Qualcomm ≫ Sm8150 Version -
Qualcomm ≫ Sm8250 Firmware Version -
   Qualcomm ≫ Sm8250 Version -
Qualcomm ≫ Sxr2130 Firmware Version -
   Qualcomm ≫ Sxr2130 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.113
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin
Broken Link
https://www.qualcomm.com/company/product-security/bulletins/august-2020-security-bulletin
Vendor Advisory