CVE-2020-3652
Summary
| CVE | CVE-2020-3652 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-16 11:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Possible buffer over-read issue in windows x86 wlan driver function while processing beacon or request frame due to lack of check of length of variable received. in Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, SDM850 |
Risk And Classification
Problem Types: CWE-20 | CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qualcomm | Msm8998 | - | All | All | All |
| Hardware | Qualcomm | Msm8998 | - | All | All | All |
| Operating System | Qualcomm | Msm8998 Firmware | - | All | All | All |
| Operating System | Qualcomm | Msm8998 Firmware | - | All | All | All |
| Hardware | Qualcomm | Qca6390 | - | All | All | All |
| Hardware | Qualcomm | Qca6390 | - | All | All | All |
| Operating System | Qualcomm | Qca6390 Firmware | - | All | All | All |
| Operating System | Qualcomm | Qca6390 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sc7180 | - | All | All | All |
| Hardware | Qualcomm | Sc7180 | - | All | All | All |
| Operating System | Qualcomm | Sc7180 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sc7180 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sc8180x | - | All | All | All |
| Hardware | Qualcomm | Sc8180x | - | All | All | All |
| Operating System | Qualcomm | Sc8180x Firmware | - | All | All | All |
| Operating System | Qualcomm | Sc8180x Firmware | - | All | All | All |
| Hardware | Qualcomm | Sdm850 | - | All | All | All |
| Hardware | Qualcomm | Sdm850 | - | All | All | All |
| Operating System | Qualcomm | Sdm850 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sdm850 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| April 2020 Bulletin | Qualcomm | CONFIRM | www.qualcomm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.