PT-2024-10761 · Broadcom+1 · Broadcom Wireless Combo Chips+1
Francesco Gringoli
+1
·
Published
2024-11-10
·
Updated
2024-11-26
·
CVE-2020-10368
CVSS v3.1
3.5
Low
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cypress (and Broadcom) Wireless Combo chips versions prior to the January 2021 firmware update
Description
The issue allows memory read access via a "Spectra" attack when a January 2021 firmware update is not present. This affects specific versions of Cypress (and Broadcom) Wireless Combo chips. Users are urged to update to the latest version and apply all recommended patches to mitigate potential threats.
Recommendations
As a temporary workaround, consider disabling the vulnerable function until a patch is available.
Update to the latest firmware and apply all recommended patches to mitigate potential threats.
Restrict access to vulnerable modules to minimize the risk of exploitation.
Avoid using vulnerable parameters in affected API endpoints until the issue is resolved.
Fix
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Broadcom Wireless Combo Chips
Cypress Wireless Combo Chips