Vulnerability Name: | CVE-2020-3636 (CCN-187958) |
Assigned: | 2019-12-17 |
Published: | 2020-08-05 |
Updated: | 2020-09-14 |
Summary: | u'Out of bound writes happen when accessing usage_table header entry beyond the memory allocated for the header' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, QCS610, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130
|
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High | 8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Local Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High |
|
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)Exploitability Metrics: | Access Vector (AV): Local Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2020-3636
Source: XF Type: UNKNOWN qualcomm-cve20203636-code-exec(187958)
Source: CONFIRM Type: Broken Link https://www.qualcomm.com/company/product-security/bulletins/august-2020-bulletin
Source: CCN Type: Qualcomm Web site August 2020 Security Bulletin
Source: MISC Type: Vendor Advisory https://www.qualcomm.com/company/product-security/bulletins/august-2020-security-bulletin
|
Vulnerable Configuration: | Configuration 1: cpe:/o:qualcomm:kamorta_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:kamorta:-:*:*:*:*:*:*:* Configuration 2: cpe:/o:qualcomm:qcs404_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:qcs404:-:*:*:*:*:*:*:* Configuration 3: cpe:/o:qualcomm:qcs610_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:qcs610:-:*:*:*:*:*:*:* Configuration 4: cpe:/o:qualcomm:rennell_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:rennell:-:*:*:*:*:*:*:* Configuration 5: cpe:/o:qualcomm:sc7180_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:sc7180:-:*:*:*:*:*:*:* Configuration 6: cpe:/o:qualcomm:sdx55_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:sdx55:-:*:*:*:*:*:*:* Configuration 7: cpe:/o:qualcomm:sm6150_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:sm6150:-:*:*:*:*:*:*:* Configuration 8: cpe:/o:qualcomm:sm7150_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:sm7150:-:*:*:*:*:*:*:* Configuration 9: cpe:/o:qualcomm:sm8250_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:sm8250:-:*:*:*:*:*:*:* Configuration 10: cpe:/o:qualcomm:sxr2130_firmware:-:*:*:*:*:*:*:*AND cpe:/h:qualcomm:sxr2130:-:*:*:*:*:*:*:* Configuration CCN 1: cpe:/h:qualcomm:snapdragon_mobile:-:*:*:*:*:*:*:*OR cpe:/h:qualcomm:snapdragon_auto:-:*:*:*:*:*:*:*OR cpe:/h:qualcomm:snapdragon_compute:-:*:*:*:*:*:*:*OR cpe:/h:qualcomm:snapdragon_consumer_internet_of_things:-:*:*:*:*:*:*:*OR cpe:/o:qualcomm:snapdragon_wired_infrastructure_&_networking:-:*:*:*:*:*:*:* Denotes that component is vulnerable |
BACK |
qualcomm kamorta firmware -
qualcomm kamorta -
qualcomm qcs404 firmware -
qualcomm qcs404 -
qualcomm qcs610 firmware -
qualcomm qcs610 -
qualcomm rennell firmware -
qualcomm rennell -
qualcomm sc7180 firmware -
qualcomm sc7180 -
qualcomm sdx55 firmware -
qualcomm sdx55 -
qualcomm sm6150 firmware -
qualcomm sm6150 -
qualcomm sm7150 firmware -
qualcomm sm7150 -
qualcomm sm8250 firmware -
qualcomm sm8250 -
qualcomm sxr2130 firmware -
qualcomm sxr2130 -
qualcomm snapdragon mobile -
qualcomm snapdragon auto -
qualcomm snapdragon compute -
qualcomm snapdragon consumer internet of things -
qualcomm snapdragon wired infrastructure & networking -