The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
2020-02-03T21:15:11.487
2024-11-21T04:51:44.607
Modified
CVSSv3.1: 7.9 (HIGH)
AV:A/AC:L/Au:N/C:C/I:C/A:C
6.5
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | synology | router_manager | 1.2 | Yes |
Operating System | broadcom | bcm4339_firmware | - | Yes |
Hardware | broadcom | bcm4339 | - | No |