Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-15126

Опубликовано: 05 фев. 2020
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.

Отчет

This issue is present in the Broadcom Wi-Fi client devices firmware and is not fixable in software. While Red Hat ships certain hardware firmware binary blobs via linux-firmware package we rely on the hardware vendors to populate (and document) these firmware binary blobs with updated firmwares at their discretion. As a consequence, we are currently unable to tell whether current linux-firmware packages address this particular vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7linux-firmwareWill not fix
Red Hat Enterprise Linux 8linux-firmwareWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-358->CWE-300
https://bugzilla.redhat.com/show_bug.cgi?id=1807728linux-firmware: Transmission of data encrypted with an all-zero session key after disassociation

EPSS

Процентиль: 92%
0.07993
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
nvd
больше 5 лет назад

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.

msrc
больше 2 лет назад

MITRE: CVE-2019-15126 Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device

suse-cvrf
больше 3 лет назад

Security update for kernel-firmware

suse-cvrf
больше 3 лет назад

Security update for kernel-firmware

suse-cvrf
больше 3 лет назад

Security update for kernel-firmware

EPSS

Процентиль: 92%
0.07993
Низкий

3.1 Low

CVSS3