MEDIUM · 5.5

CVE-2020-3679

u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known address including code segments' in Snapdragon Auto, Snapdragon Compute, Snapdr...

Vulnerability Description

u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known address including code segments' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Bitra, Kamorta, Nicobar, QCS404, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
QualcommBitra Firmware-
QualcommBitra-
QualcommKamorta Firmware-
QualcommKamorta-
QualcommNicobar Firmware-
QualcommNicobar-
QualcommQcs404 Firmware-
QualcommQcs404-
QualcommQcs610 Firmware-
QualcommQcs610-
QualcommRennell Firmware-
QualcommRennell-
QualcommSa6155P Firmware-
QualcommSa6155P-
QualcommSa8155P Firmware-
QualcommSa8155P-
QualcommSaipan Firmware-
QualcommSaipan-
QualcommSc7180 Firmware-
QualcommSc7180-

References

FAQ

What is CVE-2020-3679?

CVE-2020-3679 is a vulnerability with a CVSS score of 5.5 (MEDIUM). u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known address including code segments' in Snapdragon Auto, Snapdragon Compute, Snapdr...

How severe is CVE-2020-3679?

CVE-2020-3679 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-3679?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Bitra Firmware, Qualcomm Bitra, Qualcomm Kamorta Firmware, Qualcomm Kamorta, Qualcomm Nicobar Firmware.