« Back to list

CVE-2020-3653

Status: ModifiedCritical (9.1)—

Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from userspace in Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, SDM850

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (5)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2020-3653",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 9.2,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@qualcomm.com",
      "affectedData": [
        {
          "vendor": "Qualcomm, Inc.",
          "product": "Snapdragon Compute, Snapdragon Connectivity",
          "versions": [
            {
              "status": "affected",
              "version": "MSM8998, QCA6390, SC7180, SC8180X, SDM850"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-04-16T11:15:15.793",
  "references": [
    {
      "url": "https://www.qualcomm.com/company/product-security/bulletins/april-2020-bulletin",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "https://www.qualcomm.com/company/product-security/bulletins/april-2020-bulletin",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        },
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Possible buffer over-read in windows wlan driver function due to lack of check of length of variable received from userspace in Snapdragon Compute, Snapdragon Connectivity in MSM8998, QCA6390, SC7180, SC8180X, SDM850"
    },
    {
      "lang": "es",
      "value": "Una posible lectura excesiva del búfer en la función del controlador wlan de Windows debido a una falta de comprobación de la longitud de la variable recibida desde el espacio del usuario en los productos Snapdragon Compute, Snapdragon Connectivity en versiones MSM8998, QCA6390, SC7180, SC8180X, SDM850."
    }
  ],
  "lastModified": "2026-06-17T03:18:47.477",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qualcomm:msm8998_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E9154AF-E52E-4E84-9322-2CA7EBD3E6FE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qualcomm:msm8998:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4796F9BD-61B3-45ED-B5E3-B061887285E2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qualcomm:qca6390_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96FBD6DF-F174-4690-AA3D-1E8974E3627F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qualcomm:qca6390:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A3BF86E1-3FAC-4A42-8C01-5944C6C30AE5"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qualcomm:sc7180_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "792A18B7-E775-4AF4-A8C4-D434400317B0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qualcomm:sc7180:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B5170B38-0976-49BB-A916-5BE44C567218"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qualcomm:sc8180x_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30A45C1A-C921-42B5-9237-367245023B45"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qualcomm:sc8180x:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "56C9D979-F214-4CD4-8CF9-43BC804BB179"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:qualcomm:sdm850_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3ADE826-C55D-4731-80B9-164FEA290FAC"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:qualcomm:sdm850:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8ED4F8FE-32DB-4696-A3AD-A9D7CB7E513A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "product-security@qualcomm.com"
}