PT-2017-2984 · Broadcom · Bcm4355C0
Gal Beniamini
·
Published
2017-06-12
·
Updated
2019-03-13
·
CVE-2017-11120
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Broadcom BCM4355C0 Wi-Fi chips version 9.44.78.27.0.1.56
Description
The issue is caused by a buffer overflow in the Wi-Fi firmware. An attacker can craft a malformed RRM neighbor report frame to trigger this overflow. Exploitation of the issue may allow a remote attacker to impact the confidentiality, integrity, and availability of data.
Recommendations
For Broadcom BCM4355C0 Wi-Fi chips version 9.44.78.27.0.1.56, consider disabling the Wi-Fi firmware until a patch is available to prevent exploitation of the buffer overflow.
As a temporary workaround, restrict access to the RRM neighbor report frame to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bcm4355C0