CVE-2020-3674
Last modified
CVE-2020-3674 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Information can leak into userspace due to improper transfer of data from kernel to userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Nicobar, QCS405, Saipan, SC8180X, SDX55, SM8150, SM8250, SXR2130. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Information can leak into userspace due to improper transfer of data from kernel to userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Nicobar, QCS405, Saipan, SC8180X, SDX55, SM8150, SM8250, SXR2130
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Nicobar Firmware | All versions |
| Qualcomm | Qcs405 Firmware | All versions |
| Qualcomm | Saipan Firmware | All versions |
| Qualcomm | Sc8180x Firmware | All versions |
| Qualcomm | Sdx55 Firmware | All versions |
| Qualcomm | Sm8150 Firmware | All versions |
| Qualcomm | Sm8250 Firmware | All versions |
| Qualcomm | Sxr2130 Firmware | All versions |
References
- https://www.qualcomm.com/company/product-security/bulletins/september-2020-bulletinPatch, Vendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/september-2020-bulletinPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-3674?
How severe is CVE-2020-3674?
How do I fix CVE-2020-3674?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-36732The crypto-js package before 3.2.1 for Node.js generates ran…5.3
- CVE-2020-36735The WP ERP | Complete HR solution with recruitment & job lis…4.3
- CVE-2020-36736The WooCommerce Checkout & Funnel Builder by CartFlows plugi…4.3
- CVE-2020-36737The Import / Export Customizer Settings plugin for WordPress…4.3
- CVE-2020-36738The Cool Timeline (Horizontal & Vertical Timeline) plugin fo…4.3
- CVE-2020-36739The Feed Them Social – Page, Post, Video, and Photo Gallerie…4.3
- CVE-2020-36740The Radio Buttons for Taxonomies plugin for WordPress is vul…8.8
- CVE-2020-36741The MultiVendorX plugin for WordPress is vulnerable to Cross…4.3
- CVE-2020-36742The Custom Field Template plugin for WordPress is vulnerable…4.3
- CVE-2020-36743The Product Catalog Simple plugin for WordPress is vulnerabl…4.3
- CVE-2020-36744The NotificationX plugin for WordPress is vulnerable to Cros…4.3
- CVE-2020-36745The WP Project Manager plugin for WordPress is vulnerable to…8.8
Are you affected by CVE-2020-3674?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
