CVE-2020-3657 - Qualcomm Msm8953 Firmware, Qualcomm Ipq8074 Firmware and Qualcomm Sdx24 Firmware

Critical 9.8

u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through webserver due to lack of array bound check.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8953, MSM8996AU, QCA6574AU, QCS405, QCS610, QRB5165, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SDX55, SM8250

Affected software

Qualcomm Msm8953 Firmware

Qualcomm Ipq8074 Firmware

Qualcomm Sdx24 Firmware

Qualcomm Qcs610 Firmware

Qualcomm Ipq6018 Firmware

Qualcomm Apq8053 Firmware

Qualcomm Apq8096au Firmware

Qualcomm Mdm9607 Firmware

Qualcomm Apq8009 Firmware

Qualcomm Msm8909w Firmware

Qualcomm Ipq8064 Firmware

Qualcomm Sdm429 Firmware

Qualcomm Mdm9206 Firmware

Qualcomm Ipq4019 Firmware

Qualcomm Sdm429w Firmware

Qualcomm Apq8017 Firmware

Qualcomm Mdm9207c Firmware

Qualcomm Sdm632 Firmware

Qualcomm Sdm845 Firmware

Qualcomm Sdx55 Firmware

Qualcomm Msm8996au Firmware

Qualcomm Sda660 Firmware

Qualcomm Sdm636 Firmware

Qualcomm Sdm630 Firmware

Qualcomm Apq8098 Firmware

Qualcomm Mdm9640 Firmware

Qualcomm Sda845 Firmware

Qualcomm Sdm660 Firmware

Qualcomm Qcs405 Firmware

Qualcomm Mdm9650 Firmware

Qualcomm Sm8250 Firmware

Qualcomm Mdm9150 Firmware

Qualcomm Qrb5165 Firmware

Qualcomm Sc8180x Firmware

Qualcomm Msm8905 Firmware

Qualcomm Sdx20 Firmware

Qualcomm Qca6574au Firmware

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.