CVE-2020-3702

u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MSM8909W, MSM8996AU, QCA9531, QCN5502, QCS405, SDX20, SM6150, SM7150
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:apq8053_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8053:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:ipq4019_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ipq4019:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:qualcomm:ipq8064_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ipq8064:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:msm8909w:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:msm8996au:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:qualcomm:qca9531_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qca9531:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:qualcomm:qcn5502_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcn5502:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:qualcomm:qcs405_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:qcs405:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:qualcomm:sdx20_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sdx20:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:qualcomm:sm6150_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm6150:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:qualcomm:sm7150_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm7150:-:*:*:*:*:*:*:*

Configuration 12 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:a:arista:access_point:*:*:*:*:*:*:*:*
OR cpe:2.3:h:arista:av2:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:c-75:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:c75-e:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:o-90:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:o90e:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:w-68:-:*:*:*:*:*:*:*

Configuration 14 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

06 Jan 2022, 14:19

Type Values Removed Values Added
References (MLIST) https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html - (MLIST) https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html - Mailing List, Third Party Advisory
References (MLIST) https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html - (MLIST) https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html - Mailing List, Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

17 Dec 2021, 01:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html -

16 Oct 2021, 01:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html -

12 Oct 2021, 14:30

Type Values Removed Values Added
CPE cpe:2.3:h:arista:o-90:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:av2:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:c75-e:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:w-68:-:*:*:*:*:*:*:*
cpe:2.3:a:arista:access_point:*:*:*:*:*:*:*:*
cpe:2.3:h:arista:c-75:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:o90e:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
CVSS v2 : 5.0
v3 : 7.5
v2 : 3.3
v3 : 6.5
References (DEBIAN) https://www.debian.org/security/2021/dsa-4978 - (DEBIAN) https://www.debian.org/security/2021/dsa-4978 - Third Party Advisory
References (CONFIRM) https://www.arista.com/en/support/advisories-notices/security-advisories/11998-security-advisory-58 - (CONFIRM) https://www.arista.com/en/support/advisories-notices/security-advisories/11998-security-advisory-58 - Third Party Advisory

25 Sep 2021, 15:15

Type Values Removed Values Added
CWE NVD-CWE-noinfo CWE-319
References
  • (DEBIAN) https://www.debian.org/security/2021/dsa-4978 -

Information

Published : 2020-09-08 10:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-3702

Mitre link : CVE-2020-3702

CVE.ORG link : CVE-2020-3702


JSON object : View

Products Affected

arista

  • c75-e
  • w-68
  • o-90
  • o90e
  • c-75
  • access_point
  • av2

qualcomm

  • qcn5502_firmware
  • ipq4019
  • ipq4019_firmware
  • apq8053_firmware
  • msm8909w_firmware
  • sm6150_firmware
  • sm7150_firmware
  • msm8909w
  • qcs405_firmware
  • qca9531_firmware
  • sdx20
  • ipq8064
  • qcs405
  • ipq8064_firmware
  • qca9531
  • msm8996au_firmware
  • sm6150
  • sm7150
  • sdx20_firmware
  • apq8053
  • qcn5502
  • msm8996au

debian

  • debian_linux
CWE
CWE-319

Cleartext Transmission of Sensitive Information