Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rfg-8q34-prmp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

EPSS

Процентиль: 80%
0.01413
Низкий

Связанные уязвимости

CVSS3: 7.9
nvd
около 6 лет назад

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость функции wlc_wpa_plumb_gtk драйвера Wi-Fi Broadcom wl, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

msrc
больше 6 лет назад

Microsoft HoloLens Remote Code Execution Vulnerabilities

EPSS

Процентиль: 80%
0.01413
Низкий