Vulnerability Details CVE-2020-3703
u'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode received from central device(This CVE is equivalent to Link Layer Length Overfow issue (CVE-2019-16336,CVE-2019-17519) and Silent Length Overflow issue(CVE-2019-17518) mentioned in sweyntooth paper)' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8053, APQ8076, AR9344, Bitra, Kamorta, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8917, MSM8937, MSM8940, MSM8953, Nicobar, QCA6174A, QCA9377, QCM2150, QCM6125, QCS404, QCS405, QCS605, QCS610, QM215, Rennell, SC8180X, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150, SXR1130
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-3703
-
cpe:2.3:h:qualcomm:apq8053:-
-
cpe:2.3:h:qualcomm:apq8076:-
-
cpe:2.3:h:qualcomm:ar9344:-
-
cpe:2.3:h:qualcomm:bitra:-
-
cpe:2.3:h:qualcomm:kamorta:-
-
cpe:2.3:h:qualcomm:mdm9206:-
-
cpe:2.3:h:qualcomm:mdm9207c:-
-
cpe:2.3:h:qualcomm:mdm9607:-
-
cpe:2.3:h:qualcomm:msm8905:-
-
cpe:2.3:h:qualcomm:msm8917:-
-
cpe:2.3:h:qualcomm:msm8937:-
-
cpe:2.3:h:qualcomm:msm8940:-
-
cpe:2.3:h:qualcomm:msm8953:-
-
cpe:2.3:h:qualcomm:nicobar:-
-
cpe:2.3:h:qualcomm:qca6174a:-
-
cpe:2.3:h:qualcomm:qca9377:-
-
cpe:2.3:h:qualcomm:qcm2150:-
-
cpe:2.3:h:qualcomm:qcm6125:-
-
cpe:2.3:h:qualcomm:qcs404:-
-
cpe:2.3:h:qualcomm:qcs405:-
-
cpe:2.3:h:qualcomm:qcs605:-
-
cpe:2.3:h:qualcomm:qcs610:-
-
cpe:2.3:h:qualcomm:qm215:-
-
cpe:2.3:h:qualcomm:rennell:-
-
cpe:2.3:h:qualcomm:sc8180x:-
-
cpe:2.3:h:qualcomm:sdm429:-
-
cpe:2.3:h:qualcomm:sdm439:-
-
cpe:2.3:h:qualcomm:sdm450:-
-
cpe:2.3:h:qualcomm:sdm630:-
-
cpe:2.3:h:qualcomm:sdm632:-
-
cpe:2.3:h:qualcomm:sdm636:-
-
cpe:2.3:h:qualcomm:sdm660:-
-
cpe:2.3:h:qualcomm:sdm670:-
-
cpe:2.3:h:qualcomm:sdm710:-
-
cpe:2.3:h:qualcomm:sdm845:-
-
cpe:2.3:h:qualcomm:sdx20:-
-
cpe:2.3:h:qualcomm:sdx24:-
-
cpe:2.3:h:qualcomm:sm6150:-
-
cpe:2.3:h:qualcomm:sm7150:-
-
cpe:2.3:h:qualcomm:sm8150:-
-
cpe:2.3:h:qualcomm:sxr1130:-
-
cpe:2.3:o:qualcomm:apq8053_firmware:-
-
cpe:2.3:o:qualcomm:apq8076_firmware:-
-
cpe:2.3:o:qualcomm:ar9344_firmware:-
-
cpe:2.3:o:qualcomm:bitra_firmware:-
-
cpe:2.3:o:qualcomm:kamorta_firmware:-
-
cpe:2.3:o:qualcomm:mdm9206_firmware:-
-
cpe:2.3:o:qualcomm:mdm9207c_firmware:-
-
cpe:2.3:o:qualcomm:mdm9607_firmware:-
-
cpe:2.3:o:qualcomm:msm8905_firmware:-
-
cpe:2.3:o:qualcomm:msm8917_firmware:-
-
cpe:2.3:o:qualcomm:msm8937_firmware:-
-
cpe:2.3:o:qualcomm:msm8940_firmware:-
-
cpe:2.3:o:qualcomm:msm8953_firmware:-
-
cpe:2.3:o:qualcomm:nicobar_firmware:-
-
cpe:2.3:o:qualcomm:qca6174a_firmware:-
-
cpe:2.3:o:qualcomm:qca9377_firmware:-
-
cpe:2.3:o:qualcomm:qcm2150_firmware:-
-
cpe:2.3:o:qualcomm:qcm6125_firmware:-
-
cpe:2.3:o:qualcomm:qcs404_firmware:-
-
cpe:2.3:o:qualcomm:qcs405_firmware:-
-
cpe:2.3:o:qualcomm:qcs605_firmware:-
-
cpe:2.3:o:qualcomm:qcs610_firmware:-
-
cpe:2.3:o:qualcomm:qm215_firmware:-
-
cpe:2.3:o:qualcomm:rennell_firmware:-
-
cpe:2.3:o:qualcomm:sc8180x_firmware:-
-
cpe:2.3:o:qualcomm:sdm429_firmware:-
-
cpe:2.3:o:qualcomm:sdm439_firmware:-
-
cpe:2.3:o:qualcomm:sdm450_firmware:-
-
cpe:2.3:o:qualcomm:sdm630_firmware:-
-
cpe:2.3:o:qualcomm:sdm632_firmware:-
-
cpe:2.3:o:qualcomm:sdm636_firmware:-
-
cpe:2.3:o:qualcomm:sdm660_firmware:-
-
cpe:2.3:o:qualcomm:sdm670_firmware:-
-
cpe:2.3:o:qualcomm:sdm710_firmware:-
-
cpe:2.3:o:qualcomm:sdm845_firmware:-
-
cpe:2.3:o:qualcomm:sdx20_firmware:-
-
cpe:2.3:o:qualcomm:sdx24_firmware:-
-
cpe:2.3:o:qualcomm:sm6150_firmware:-
-
cpe:2.3:o:qualcomm:sm7150_firmware:-
-
cpe:2.3:o:qualcomm:sm8150_firmware:-
-
cpe:2.3:o:qualcomm:sxr1130_firmware:-