Saipan Firmware
Vendor:
First CVE: Feb 7, 2020 · Active for 6 years
95
Total CVEs
More Total CVEs than 99% of tracked products
95.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Saipan Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2020
6 years ago
Most Recent CVE
Nov 2, 2020
2,094 days ago
CVE Severity & Scoring
Saipan Firmware95 CVEs
8%
64%
27%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local63 (66.3%)
Network32 (33.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low92 (96.8%)
High3 (3.2%)
Unknown0 (0.0%)
User Interaction
None94 (98.9%)
Unknown0 (0.0%)
Required1 (1.1%)
Privileges Required
Low62 (65.3%)
High0 (0.0%)
None33 (34.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (95 CVEs).
95 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-3692CRITICAL u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received from server' in Snapdragon Aut | Nov 2, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-3673CRITICAL u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check to validate the index length' in Snapdragon Auto, Snapdrago | Nov 2, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-3675CRITICAL u'Potential integer underflow while parsing Service Info and IPv6 link-local TLVs that comes as part of NDPE attribute' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectiv | Sep 8, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-3698CRITICAL Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Cons | Jul 30, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-3663CRITICAL Buffer over-write may occur during fetching track decoder specific information if cb size exceeds buffer size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapd | Jun 22, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-3641CRITICAL Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapd | Jun 2, 2020 | 9.8 | 30 | NO | NO |
CVE-2019-14095CRITICAL Buffer overflow occurs while processing LMP packet in which name length parameter exceeds value specified in BT-specification in Snapdragon Auto, Snapdragon Compute, Snapdragon Con | Mar 5, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-3688CRITICAL Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sna | Jul 30, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-3671CRITICAL Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snap | Jul 30, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-3662CRITICAL Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer | Jun 22, 2020 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (95 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (95 CVEs).
Media Mentions
Signals from CVEs in this product scope (95 CVEs).
Top CNAs Publishing CVEs For Saipan Firmware
Top CWEs
Versions
No cataloged versions.