Learn about CVE-2020-3702 affecting Qualcomm Snapdragon products, leading to information disclosure over the air due to Wi-Fi encryption issues. Find mitigation steps and updates here.
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking by Qualcomm, Inc. are affected by a vulnerability that can lead to information disclosure over the air.
Understanding CVE-2020-3702
This CVE involves a specific timing issue in WLAN devices that can result in improper Wi-Fi encryption, potentially exposing sensitive information.
What is CVE-2020-3702?
This vulnerability allows for the disclosure of information over the air due to internal errors in WLAN devices, leading to improper layer 2 Wi-Fi encryption.
The Impact of CVE-2020-3702
The vulnerability poses a risk of information disclosure for a specific set of traffic within the affected Qualcomm products and versions.
Technical Details of CVE-2020-3702
The following technical details provide insight into the nature of the vulnerability.
Vulnerability Description
The issue arises from specifically timed and handcrafted traffic that triggers internal errors in WLAN devices, resulting in improper layer 2 Wi-Fi encryption.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited by sending specifically crafted traffic to the affected WLAN devices, causing internal errors and leading to information disclosure.
Mitigation and Prevention
To address CVE-2020-3702, the following steps are recommended:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates