7.5

CVE-2020-3700

Possible out of bounds read due to a missing bounds check and could lead to local information disclosure in the wifi driver with no additional execution privileges needed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8909W, MSM8996AU, QCA6574AU, QCA9531, QCA9558, QCA9980, SC8180X, SDM439, SDX55, SM8150, SM8250, SXR2130

Data is provided by the National Vulnerability Database (NVD)
QualcommApq8053 Firmware Version-
   QualcommApq8053 Version-
QualcommApq8096au Firmware Version-
   QualcommApq8096au Version-
QualcommIpq4019 Firmware Version-
   QualcommIpq4019 Version-
QualcommIpq8064 Firmware Version-
   QualcommIpq8064 Version-
QualcommIpq8074 Firmware Version-
   QualcommIpq8074 Version-
QualcommMdm9607 Firmware Version-
   QualcommMdm9607 Version-
QualcommMsm8909w Firmware Version-
   QualcommMsm8909w Version-
QualcommMsm8996au Firmware Version-
   QualcommMsm8996au Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca9531 Firmware Version-
   QualcommQca9531 Version-
QualcommQca9558 Firmware Version-
   QualcommQca9558 Version-
QualcommQca9980 Firmware Version-
   QualcommQca9980 Version-
QualcommSc8180x Firmware Version-
   QualcommSc8180x Version-
QualcommSdm439 Firmware Version-
   QualcommSdm439 Version-
QualcommSdx55 Firmware Version-
   QualcommSdx55 Version-
QualcommSm8150 Firmware Version-
   QualcommSm8150 Version-
QualcommSm8250 Firmware Version-
   QualcommSm8250 Version-
QualcommSxr2130 Firmware Version-
   QualcommSxr2130 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.44% 0.6
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.