2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2020-3668" ,
"sourceIdentifier" : "product-security@qualcomm.com" ,
"published" : "2020-09-08T10:15:16.153" ,
2024-11-23 13:10:58 +00:00
"lastModified" : "2024-11-21T05:31:32.323" ,
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while parsing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SA415M, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130"
} ,
{
"lang" : "es" ,
"value" : "Un Desbordamiento del B\u00fafer mientras se analiza trama MCBC habilitadas de PMF debido a que la longitud de la trama es menor de lo esperado mientras se analiza en los productos Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking en versiones IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SA415M, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-11-23 13:10:58 +00:00
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-11-23 13:10:58 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:C/I:C/A:C" ,
2024-11-23 13:10:58 +00:00
"baseScore" : 10.0 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "COMPLETE" ,
"integrityImpact" : "COMPLETE" ,
2024-11-23 13:10:58 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "HIGH" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 10.0 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-120"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:ipq6018_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B04589FF-F299-4EF6-A57B-1AD145372DBB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:ipq6018:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FDC1ADAD-DA77-47EF-8DB9-C36961C560C2"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:ipq8074_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2914BF98-E69C-4C8D-8B10-759642ADD7B4"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:ipq8074:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2118C404-402F-463C-8160-3CC3B703DF30"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:kamorta_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4C17D128-D249-463B-B21B-F5B01265726A"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:kamorta:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4ECFB565-9C4D-4F58-AD4E-283276688F00"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:nicobar_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "490B208B-BBF3-4C58-A2BD-626DF6841AEE"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:nicobar:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "572C4751-B805-430C-B26B-2DF661B362C2"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:qca6390_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "96FBD6DF-F174-4690-AA3D-1E8974E3627F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:qca6390:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A3BF86E1-3FAC-4A42-8C01-5944C6C30AE5"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:qca8081_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1D1C53DC-D2F3-4C92-9725-9A85340AF026"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:qca8081:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "ED0585FF-E390-46E8-8701-70964A4057BB"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:qcn7605_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9C9D1966-30F0-414D-BE75-0A14B12A1457"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:qcn7605:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CD28C87D-1D28-4C84-BFE4-56EE3BF2C6B0"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:qcs404_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2A2F7E6B-D499-4698-A203-A12725E51DFF"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:qcs404:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B172AA65-B693-48DF-9D5A-7BB6FCC4A2A3"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:qcs405_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "36F5A18B-8C9E-4A38-B994-E3E2696BB83D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:qcs405:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B703667D-DE09-40AF-BA44-E0E56252A790"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:qcs605_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B05FD66D-13A6-40E9-A64B-E428378F237E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:qcs605:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D0D665C1-3EBA-42F2-BF56-55E6C365F7DF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:rennell_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D49376E9-D31E-4E84-9401-45859263F26C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:rennell:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B6D66742-81FA-46D6-B7A2-5460923D81A8"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sa415m_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D4387DBE-67F7-4E95-A2B0-828211EBDC22"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sa415m:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AC798E06-0A2E-4DAD-81D1-9B2FAE6327C0"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sc7180_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "792A18B7-E775-4AF4-A8C4-D434400317B0"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sc7180:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B5170B38-0976-49BB-A916-5BE44C567218"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sc8180x_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "30A45C1A-C921-42B5-9237-367245023B45"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sc8180x:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "56C9D979-F214-4CD4-8CF9-43BC804BB179"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sda845_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "022D7D87-F60F-4DD2-9E0B-A9DFD3D69B22"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sda845:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "37FA5777-1B35-4BD1-BB81-CB5DE62F3D56"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm670_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "00865826-86AE-425F-BE6F-162F611FB200"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm670:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0CC0441C-C30B-4D99-9BAD-C1E4387302BB"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm710_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D045BE4B-BC19-4A51-90E6-00C18389C81B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm710:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4F006960-CDE3-4E74-B4F0-2C4B2CA93959"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm845_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DED4B719-53B5-4D16-B3FA-ADE29D28ED86"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm845:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D342C86B-E184-457C-9F72-BD853ED79425"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sdm850_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B3ADE826-C55D-4731-80B9-164FEA290FAC"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sdm850:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8ED4F8FE-32DB-4696-A3AD-A9D7CB7E513A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sm6150_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8ABE492A-3755-4969-9DEB-4B85EBB84644"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sm6150:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E3D3787B-6ACC-4591-B041-01307ED66C36"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sm7150_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F63A748F-2236-4486-83F1-DE4BCBE5D56D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sm7150:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "184F3DFC-27E8-48AC-B46C-C589DBCBF030"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sm8150_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9286B1E8-E39F-4DAA-8969-311CA2A0A8AA"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sm8150:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "19B9AE36-87A9-4EE7-87C8-CCA2DCF51039"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:qualcomm:sxr1130_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "096F7BA5-FF58-416B-93EF-733B16326C86"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:qualcomm:sxr1130:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7AF958FB-1611-4102-A2DB-8D4311AE0D72"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin" ,
"source" : "product-security@qualcomm.com" ,
"tags" : [
"Broken Link" ,
"Vendor Advisory"
]
2024-11-23 13:10:58 +00:00
} ,
{
"url" : "https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Broken Link" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}