Description
Out of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
References (2)
Core 2
Core References
Broken Link x_refsource_confirm
https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin
Scores
CVSS v3
9.8
EPSS
0.0027
EPSS Percentile
50.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-125
Status
published
Products (50)
qualcomm/apq8009
qualcomm/apq8016
qualcomm/apq8017
qualcomm/apq8037
qualcomm/apq8039
qualcomm/apq8053
qualcomm/apq8064au
qualcomm/apq8076
qualcomm/apq8092
qualcomm/apq8094
... and 40 more
Published
Jan 21, 2021
Tracked Since
Feb 18, 2026