7.8

CVE-2020-3645

Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130, SXR2130

Data is provided by the National Vulnerability Database (NVD)
QualcommIpq6018 Firmware Version-
   QualcommIpq6018 Version-
QualcommIpq8074 Firmware Version-
   QualcommIpq8074 Version-
QualcommKamorta Firmware Version-
   QualcommKamorta Version-
QualcommNicobar Firmware Version-
   QualcommNicobar Version-
QualcommQca6390 Firmware Version-
   QualcommQca6390 Version-
QualcommQca8081 Firmware Version-
   QualcommQca8081 Version-
QualcommQcs404 Firmware Version-
   QualcommQcs404 Version-
QualcommQcs405 Firmware Version-
   QualcommQcs405 Version-
QualcommRennell Firmware Version-
   QualcommRennell Version-
QualcommSc7180 Firmware Version-
   QualcommSc7180 Version-
QualcommSc8180x Firmware Version-
   QualcommSc8180x Version-
QualcommSda845 Firmware Version-
   QualcommSda845 Version-
QualcommSdm670 Firmware Version-
   QualcommSdm670 Version-
QualcommSdm710 Firmware Version-
   QualcommSdm710 Version-
QualcommSdm850 Firmware Version-
   QualcommSdm850 Version-
QualcommSm6150 Firmware Version-
   QualcommSm6150 Version-
QualcommSm7150 Firmware Version-
   QualcommSm7150 Version-
QualcommSm8150 Firmware Version-
   QualcommSm8150 Version-
QualcommSxr1130 Firmware Version-
   QualcommSxr1130 Version-
QualcommSxr2130 Firmware Version-
   QualcommSxr2130 Version-
QualcommQcn7605 Firmware Version-
   QualcommQcn7605 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommSdm845 Firmware Version-
   QualcommSdm845 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.25% 0.449
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.