CVE-2019-9500

HIGH

Description

The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

References

https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html

https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff

https://kb.cert.org/vuls/id/166939/

Details

Source: MITRE

Published: 2020-01-16

Updated: 2020-01-29

Type: CWE-787

Risk Information

CVSS v2.0

Base Score: 7.9

Vector: AV:A/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 5.5

Severity: HIGH

CVSS v3.0

Base Score: 8.3

Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Impact Score: 6

Exploitability Score: 1.6

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:broadcom:brcmfmac_driver:-:*:*:*:*:*:*:*

Tenable Plugins

View all (37 total)

IDNameProductFamilySeverity
145668CentOS 8 : kernel (CESA-2019:2703)NessusCentOS Local Security Checks
high
144831EulerOS Virtualization 3.0.2.6 : kernel (EulerOS-SA-2021-1056)NessusHuawei Local Security Checks
critical
137291Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5715)NessusOracle Linux Local Security Checks
critical
133076NewStart CGSL CORE 5.05 / MAIN 5.05 : kernel-rt Multiple Vulnerabilities (NS-SA-2020-0008)NessusNewStart CGSL Local Security Checks
high
133072NewStart CGSL CORE 5.05 / MAIN 5.05 : kernel Multiple Vulnerabilities (NS-SA-2020-0002)NessusNewStart CGSL Local Security Checks
high
131983RHEL 7 : kpatch-patch (RHSA-2019:4171)NessusRed Hat Local Security Checks
high
131982RHEL 7 : kernel (RHSA-2019:4168)NessusRed Hat Local Security Checks
high
131421NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel-rt Multiple Vulnerabilities (NS-SA-2019-0222)NessusNewStart CGSL Local Security Checks
high
131411NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2019-0221)NessusNewStart CGSL Local Security Checks
high
130736EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-2274)NessusHuawei Local Security Checks
critical
130373RHEL 7 : kernel-alt (RHSA-2019:3217)NessusRed Hat Local Security Checks
high
129519RHEL 7 : kpatch-patch (RHSA-2019:2945)NessusRed Hat Local Security Checks
high
129284SUSE SLED15 / SLES15 Security Update : kernel-source-rt (SUSE-SU-2019:2430-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (SACK Panic) (SACK Slowness) (Spectre)NessusSuSE Local Security Checks
high
129020CentOS 7 : kernel (CESA-2019:2600)NessusCentOS Local Security Checks
high
128859RHEL 8 : kernel-rt (RHSA-2019:2741)NessusRed Hat Local Security Checks
high
128845Oracle Linux 8 : kernel (ELSA-2019-2703)NessusOracle Linux Local Security Checks
high
128665RHEL 8 : kernel (RHSA-2019:2703)NessusRed Hat Local Security Checks
high
128513Oracle Linux 7 : kernel (ELSA-2019-2600)NessusOracle Linux Local Security Checks
high
128501Scientific Linux Security Update : kernel on SL7.x x86_64 (20190903)NessusScientific Linux Local Security Checks
high
128498RHEL 7 : kernel-rt (RHSA-2019:2609)NessusRed Hat Local Security Checks
high
128495RHEL 7 : kernel (RHSA-2019:2600)NessusRed Hat Local Security Checks
high
126045SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:1550-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (SACK Panic) (SACK Slowness) (Spectre)NessusSuSE Local Security Checks
high
126009Debian DLA-1824-1 : linux-4.9 security update (SACK Panic) (SACK Slowness)NessusDebian Local Security Checks
high
125959Debian DSA-4465-1 : linux - security update (SACK Panic) (SACK Slowness)NessusDebian Local Security Checks
high
125667openSUSE Security Update : the Linux Kernel (openSUSE-2019-1479)NessusSuSE Local Security Checks
high
125605Amazon Linux AMI : kernel (ALAS-2019-1214)NessusAmazon Linux Local Security Checks
high
125598Amazon Linux 2 : kernel (ALAS-2019-1214)NessusAmazon Linux Local Security Checks
high
125243openSUSE Security Update : the Linux Kernel (openSUSE-2019-1404) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusSuSE Local Security Checks
high
125142Ubuntu 16.04 LTS : Linux kernel (HWE) vulnerabilities (USN-3981-2) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
high
125141Ubuntu 18.04 LTS : Linux kernel vulnerabilities (USN-3981-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
high
125140Ubuntu 18.04 LTS : Linux kernel (HWE) vulnerabilities (USN-3980-2) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
high
125139Ubuntu 18.10 : Linux kernel vulnerabilities (USN-3980-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
high
125138Ubuntu 19.04 : Linux kernel vulnerabilities (USN-3979-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
critical
125132SUSE SLES12 Security Update : kernel (SUSE-SU-2019:1242-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusSuSE Local Security Checks
high
124552Fedora 30 : kernel / kernel-headers / kernel-tools (2019-e84f6c34da)NessusFedora Local Security Checks
high
124308Fedora 28 : kernel / kernel-headers / kernel-tools (2019-1b986880ea)NessusFedora Local Security Checks
high
124284Fedora 29 : kernel / kernel-headers / kernel-tools (2019-1e8a4c6958)NessusFedora Local Security Checks
high