Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23v8-j48f-jm74

Опубликовано: 12 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation of a WPA2 four-way handshake. This lack of validation leads to a stack buffer overflow. This can result in remote code execution within the kernel. This affects Amp, Arc, Arc SL, Beam, Beam Gen 2, Beam SL, and Five.

In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation of a WPA2 four-way handshake. This lack of validation leads to a stack buffer overflow. This can result in remote code execution within the kernel. This affects Amp, Arc, Arc SL, Beam, Beam Gen 2, Beam SL, and Five.

EPSS

Процентиль: 17%
0.00054
Низкий

7.8 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 7.8
nvd
12 месяцев назад

In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation of a WPA2 four-way handshake. This lack of validation leads to a stack buffer overflow. This can result in remote code execution within the kernel. This affects Amp, Arc, Arc SL, Beam, Beam Gen 2, Beam SL, and Five.

CVSS3: 7.8
fstec
около 1 года назад

Уязвимость драйвера беспроводной сети mt_7615.ko программного обеспечения аудио устройств Sonos, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 17%
0.00054
Низкий

7.8 High

CVSS3

Дефекты

CWE-121