PT-2017-2984 · Broadcom · Bcm4355C0

Gal Beniamini

·

Published

2017-06-12

·

Updated

2019-03-13

·

CVE-2017-11120

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Broadcom BCM4355C0 Wi-Fi chips version 9.44.78.27.0.1.56
Description The issue is caused by a buffer overflow in the Wi-Fi firmware. An attacker can craft a malformed RRM neighbor report frame to trigger this overflow. Exploitation of the issue may allow a remote attacker to impact the confidentiality, integrity, and availability of data.
Recommendations For Broadcom BCM4355C0 Wi-Fi chips version 9.44.78.27.0.1.56, consider disabling the Wi-Fi firmware until a patch is available to prevent exploitation of the buffer overflow. As a temporary workaround, restrict access to the RRM neighbor report frame to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02326
CVE-2017-11120

Affected Products

Bcm4355C0