← Vulnerability feed

Vulnerability record · CVE-2020-3629 · published 8 September 2020

CVE-2020-3629: Qualcomm bitra firmware classic buffer overflow vulnerability

Qualcomm · Bitra Firmware

u'Stack out of bound issue occurs when making query to DSP capabilities due to wrong assumption was made on determining the buffer size for the DSP attributes' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Bitra, Kamorta, Rennell, SC7180, SDM845, SM6150, SM7150, SM8150, SM8250, SXR2130

7.8 CVSS 3.1 High EPSS 0.21% · top 89.5% CWE-120 · Classic buffer overflow
7.8CVSS 3.1 base score, v2 4.6
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

u'Stack out of bound issue occurs when making query to DSP capabilities due to wrong assumption was made on determining the buffer size for the DSP attributes' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Bitra, Kamorta, Rennell, SC7180, SDM845, SM6150, SM7150, SM8150, SM8250, SXR2130

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3629 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-33063Qualcomm DSP Services use-after-free memory corruptionCVE-2023-33063 is a use-after-free memory corruption flaw in Qualcomm DSP Services, triggered during a remote call from the high-level operating syst…KEVEPSS 0.67%analysed9.8CVE-2020-3639Qualcomm apq8009 firmware vulnerabilityu'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memory overflow' in Sna…EPSS 0.91%9.8CVE-2020-11193Qualcomm apq8009 firmware out-of-bounds read vulnerabilityu'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Auto, Snapdragon Compu…EPSS 0.91%9.8CVE-2020-11168Qualcomm apq8009w firmware null pointer dereference vulnerabilityu'Null-pointer dereference can occur while accessing data buffer beyond its size that leads to access the buffer beyond its range' in Snapdragon Auto…EPSS 0.91%9.8CVE-2020-11196Qualcomm apq8009 firmware memory buffer overflow vulnerabilityu'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon Auto, Snapdragon Com…EPSS 0.90%9.8CVE-2020-3703Qualcomm apq8053 firmware improper input validation vulnerabilityu'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode received from central device(T…EPSS 0.71%9.8CVE-2020-3657Qualcomm apq8009 firmware classic buffer overflow vulnerabilityu'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client through web…EPSS 28%9.8CVE-2020-3692Qualcomm agatti firmware classic buffer overflow vulnerabilityu'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2020-3629), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.