CVE-2020-3703 - Qualcomm Kamorta Firmware, Qualcomm Msm8905 Firmware and Qualcomm Msm8937 Firmware

Critical 9.8

u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode received from central device(This CVE is equivalent to Link Layer Length Overfow issue (CVE-2019-16336,CVE-2019-17519) and Silent Length Overflow issue(CVE-2019-17518) mentioned in sweyntooth paper)' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8053, APQ8076, AR9344, Bitra, Kamorta, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8917, MSM8937, MSM8940, MSM8953, Nicobar, QCA6174A, QCA9377, QCM2150, QCM6125, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SC8180X, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150, SXR1130

Affected software

Qualcomm Kamorta Firmware

Qualcomm Msm8905 Firmware

Qualcomm Msm8937 Firmware

Qualcomm Qcs605 Firmware

Qualcomm Mdm9207c Firmware

Qualcomm Sm7150 Firmware

Qualcomm Sxr1130 Firmware

Qualcomm Msm8940 Firmware

Qualcomm Sdm450 Firmware

Qualcomm Apq8076 Firmware

Qualcomm Qcs610 Firmware

Qualcomm Rennell Firmware

Qualcomm Qm215 Firmware

Qualcomm Bitra Firmware

Qualcomm Mdm9607 Firmware

Qualcomm Qca6174a Firmware

Qualcomm Sdm660 Firmware

Qualcomm Sdm636 Firmware

Qualcomm Qcs405 Firmware

Qualcomm Nicobar Firmware

Qualcomm Sdm439 Firmware

Qualcomm Sdm670 Firmware

Qualcomm Sdm429 Firmware

Qualcomm Ar9344 Firmware

Qualcomm Sdm632 Firmware

Qualcomm Sm6150 Firmware

Qualcomm Apq8053 Firmware

Qualcomm Msm8953 Firmware

Qualcomm Sdm630 Firmware

Qualcomm Msm8917 Firmware

Qualcomm Sdx20 Firmware

Qualcomm Sm8150 Firmware

Qualcomm Qca9377 Firmware

Qualcomm Qcs404 Firmware

Qualcomm Sdm710 Firmware

Qualcomm Qcm2150 Firmware

Qualcomm Sdm845 Firmware

Qualcomm Mdm9206 Firmware

Qualcomm Qcm6125 Firmware

Qualcomm Sc8180x Firmware

Qualcomm Sdx24 Firmware

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.