CVE-2020-3702

Advisory lineage Upstream: 0 Downstream: 52
Modified
Published: 08 Sept 2020, 09:31
Last modified:04 Aug 2024, 07:44

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.3% LOW
0% probability +0.04%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Sept 2020, 09:31
Published
Vulnerability first disclosed
04 Aug 2024, 07:44
Last Modified
Vulnerability information updated

Description

u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MSM8909W, MSM8996AU, QCA9531, QCN5502, QCS405, SDX20, SM6150, SM7150

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v2.0LOWScore: 3.3AV:A/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.30% Percentile: 53%

Techniques & Countermeasures

  • CWE-319Cleartext Transmission of Sensitive Information

    The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Systems

  • aristaaccess_point

    ≤ 8.8.3-12

  • debiandebian_linux

    10.0 | 9.0

  • qualcommapq8053_firmware

    na

  • qualcommipq4019_firmware

    na

  • qualcommipq8064_firmware

    na

  • qualcommmsm8909w_firmware

    na

  • qualcommmsm8996au_firmware

    na

  • qualcommqca9531_firmware

    na

  • qualcommqcn5502_firmware

    na

  • qualcommqcs405_firmware

    na

  • qualcommsdx20_firmware

    na

  • qualcommsm6150_firmware

    na

  • qualcommsm7150_firmware

    na

References (5)