Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-9501

Опубликовано: 03 фев. 2020
Источник: nvd
CVSS3: 7.9
CVSS3: 8.8
CVSS2: 8.3
EPSS Низкий

Описание

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:synology:router_manager:1.2:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:broadcom:bcm4339_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:broadcom:bcm4339:-:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02274
Низкий

7.9 High

CVSS3

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-122
CWE-787

Связанные уязвимости

github
больше 3 лет назад

The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость функции wlc_wpa_sup_eapol драйвера Wi-Fi Broadcom wl, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

msrc
больше 6 лет назад

Microsoft HoloLens Remote Code Execution Vulnerabilities

EPSS

Процентиль: 84%
0.02274
Низкий

7.9 High

CVSS3

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-122
CWE-787