Post-COVID-19 Cybersecurity Spending Update

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2020-5627
PUBLISHED: 2020-09-09

Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

CVE-2020-3617
PUBLISHED: 2020-09-09

u’Buffer over-read Issue in Q6 testbus framework due to diag packet length is not completely validated before accessing the field and leads to Information disclosure.’ in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Kamorta, Nicobar, QCS605, QCS610, Re…

CVE-2020-3634
PUBLISHED: 2020-09-09

u’Multiple Read overflows issue due to improper length check while decoding Generic NAS transport/EMM info’ in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, M…

CVE-2020-3656
PUBLISHED: 2020-09-09

u’Out of bound access can happen in MHI command process due to lack of check of command channel id value received from MHI devices’ in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ…

CVE-2020-3674
PUBLISHED: 2020-09-09

u’Information can leak into userspace due to improper transfer of data from kernel to userspace’ in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in Nicobar, QCS405, Saipan, SC8180X, SDX5…

Read More HERE

Leave a Reply