The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
2020-02-03T21:15:11.547
2024-11-21T04:51:44.727
Modified
CVSSv3.1: 7.9 (HIGH)
AV:A/AC:L/Au:N/C:C/I:C/A:C
6.5
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | synology | router_manager | 1.2 | Yes |
| Operating System | broadcom | bcm4339_firmware | - | Yes |
| Hardware | broadcom | bcm4339 | - | No |