CVE-2020-3702 is a medium-severity vulnerability affecting numerous Qualcomm Snapdragon products across various categories, including Auto, Compute, and Mobile. It allows an attacker to cause internal errors in a WLAN device through specifically timed and handcrafted traffic, leading to improper Layer 2 Wi-Fi encryption and potential information disclosure over the air. With a CVSS score of 6.5, this vulnerability has a low attack complexity and requires adjacent network access, but can result in high confidentiality impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:apq8053_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:ipq4019_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:ipq8064_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.