← Vulnerability feed

Vulnerability record · CVE-2020-3694 · published 2 November 2020

CVE-2020-3694: Qualcomm bitra firmware vulnerability

Qualcomm · Bitra Firmware

u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Voice & Music in Bitra, Nicobar, Saipan, SM6150, SM8150, SM8250, SXR2130

7.8 CVSS 3.1 High EPSS 0.25% · top 85.1%
7.8CVSS 3.1 base score, v2 4.6
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

u'Use out of range pointer issue can occur due to incorrect buffer range check during the execution of qseecom' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Voice & Music in Bitra, Nicobar, Saipan, SM6150, SM8150, SM8250, SXR2130

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3694 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-3639Qualcomm apq8009 firmware vulnerabilityu'When a non standard SIP sigcomp message is received from the network, then there may be chances of using more UDVM cycle or memory overflow' in Sna…EPSS 0.91%9.8CVE-2020-11193Qualcomm apq8009 firmware out-of-bounds read vulnerabilityu'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Auto, Snapdragon Compu…EPSS 0.91%9.8CVE-2020-11184Qualcomm qcm4290 firmware integer overflow vulnerabilityu'Possible buffer overflow will occur in video while parsing mp4 clip with crafted esds atom size.' in Snapdragon Auto, Snapdragon Compute, Snapdrago…EPSS 0.95%9.8CVE-2020-11168Qualcomm apq8009w firmware null pointer dereference vulnerabilityu'Null-pointer dereference can occur while accessing data buffer beyond its size that leads to access the buffer beyond its range' in Snapdragon Auto…EPSS 0.91%9.8CVE-2020-11196Qualcomm apq8009 firmware memory buffer overflow vulnerabilityu'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon Auto, Snapdragon Com…EPSS 0.90%9.8CVE-2020-3703Qualcomm apq8053 firmware improper input validation vulnerabilityu'Buffer over-read issue in Bluetooth peripheral firmware due to lack of check for invalid opcode and length of opcode received from central device(T…EPSS 0.71%9.8CVE-2020-3654Qualcomm agatti firmware vulnerabilityu'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying into it' in Snapdragon Auto, Sna…EPSS 0.90%9.8CVE-2020-3692Qualcomm agatti firmware classic buffer overflow vulnerabilityu'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received…EPSS 0.90%

Source: NIST National Vulnerability Database (record CVE-2020-3694), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.