CVE-2020-3622
Last modified
CVE-2020-3622 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated for NULL termination can results into memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated for NULL termination can results into memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SA415M, SA6155P, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Apq8009 | All versions |
| Qualcomm | Apq8017 | All versions |
| Qualcomm | Apq8053 | All versions |
| Qualcomm | Apq8096au | All versions |
| Qualcomm | Apq8098 | All versions |
| Qualcomm | Bitra | All versions |
| Qualcomm | Ipq6018 | All versions |
| Qualcomm | Ipq8074 | All versions |
| Qualcomm | Kamorta | All versions |
| Qualcomm | Mdm9150 | All versions |
| Qualcomm | Mdm9205 | All versions |
| Qualcomm | Mdm9206 | All versions |
| Qualcomm | Mdm9607 | All versions |
| Qualcomm | Mdm9640 | All versions |
| Qualcomm | Mdm9645 | All versions |
| Qualcomm | Mdm9650 | All versions |
| Qualcomm | Mdm9655 | All versions |
| Qualcomm | Msm8905 | All versions |
| Qualcomm | Msm8909 | All versions |
| Qualcomm | Msm8917 | All versions |
| Qualcomm | Msm8920 | All versions |
| Qualcomm | Msm8937 | All versions |
| Qualcomm | Msm8940 | All versions |
| Qualcomm | Msm8953 | All versions |
| Qualcomm | Msm8996 | All versions |
| Qualcomm | Msm8996au | All versions |
| Qualcomm | Msm8998 | All versions |
| Qualcomm | Nicobar | All versions |
| Qualcomm | Qca8081 | All versions |
| Qualcomm | Qcm2150 | All versions |
| Qualcomm | Qcn7605 | All versions |
| Qualcomm | Qcs404 | All versions |
| Qualcomm | Qcs405 | All versions |
| Qualcomm | Qcs605 | All versions |
| Qualcomm | Qcs610 | All versions |
| Qualcomm | Qm215 | All versions |
| Qualcomm | Rennell | All versions |
| Qualcomm | Sa415m | All versions |
| Qualcomm | Sa6155p | All versions |
| Qualcomm | Saipan | All versions |
| Qualcomm | Sc7180 | All versions |
| Qualcomm | Sc8180x | All versions |
| Qualcomm | Sda660 | All versions |
| Qualcomm | Sda845 | All versions |
| Qualcomm | Sdm429 | All versions |
| Qualcomm | Sdm429w | All versions |
| Qualcomm | Sdm439 | All versions |
| Qualcomm | Sdm450 | All versions |
| Qualcomm | Sdm630 | All versions |
| Qualcomm | Sdm632 | All versions |
Showing 50 of 130 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-3622?
How severe is CVE-2020-3622?
How do I fix CVE-2020-3622?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-36214An issue was discovered in the multiqueue2 crate before 0.1.…5.9
- CVE-2020-36215An issue was discovered in the hashconsing crate before 1.1.…7.5
- CVE-2020-36216An issue was discovered in Input<R> in the eventio crate bef…5.9
- CVE-2020-36217An issue was discovered in the may_queue crate through 2020-…5.9
- CVE-2020-36218An issue was discovered in the buttplug crate before 1.0.4 f…5.9
- CVE-2020-36219An issue was discovered in the atomic-option crate through 2…5.9
- CVE-2020-36220An issue was discovered in the va-ts crate before 0.0.4 for …5.9
- CVE-2020-36221An integer underflow was discovered in OpenLDAP before 2.4.5…7.5
- CVE-2020-36222A flaw was discovered in OpenLDAP before 2.4.57 leading to a…7.5
- CVE-2020-36223A flaw was discovered in OpenLDAP before 2.4.57 leading to a…7.5
- CVE-2020-36224A flaw was discovered in OpenLDAP before 2.4.57 leading to a…7.5
- CVE-2020-36225A flaw was discovered in OpenLDAP before 2.4.57 leading to a…7.5
Are you affected by CVE-2020-3622?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
