CVE-2019-9500

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

References

https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html

https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff

https://kb.cert.org/vuls/id/166939/

Details

Source: MITRE

Published: 2020-01-16

Updated: 2020-01-29

Type: CWE-787

Risk Information

CVSS v2

Base Score: 7.9

Vector: AV:A/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 5.5

Severity: HIGH

CVSS v3

Base Score: 8.3

Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Impact Score: 6

Exploitability Score: 1.6

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:broadcom:brcmfmac_driver:-:*:*:*:*:*:*:*

Tenable Plugins

View all (37 total)

IDNameProductFamilySeverity
145668CentOS 8 : kernel (CESA-2019:2703)NessusCentOS Local Security Checks
high
144831EulerOS Virtualization 3.0.2.6 : kernel (EulerOS-SA-2021-1056)NessusHuawei Local Security Checks
critical
137291Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5715)NessusOracle Linux Local Security Checks
critical
133076NewStart CGSL CORE 5.05 / MAIN 5.05 : kernel-rt Multiple Vulnerabilities (NS-SA-2020-0008)NessusNewStart CGSL Local Security Checks
high
133072NewStart CGSL CORE 5.05 / MAIN 5.05 : kernel Multiple Vulnerabilities (NS-SA-2020-0002)NessusNewStart CGSL Local Security Checks
high
131983RHEL 7 : kpatch-patch (RHSA-2019:4171)NessusRed Hat Local Security Checks
high
131982RHEL 7 : kernel (RHSA-2019:4168)NessusRed Hat Local Security Checks
high
131421NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel-rt Multiple Vulnerabilities (NS-SA-2019-0222)NessusNewStart CGSL Local Security Checks
high
131411NewStart CGSL CORE 5.04 / MAIN 5.04 : kernel Multiple Vulnerabilities (NS-SA-2019-0221)NessusNewStart CGSL Local Security Checks
high
130736EulerOS 2.0 SP3 : kernel (EulerOS-SA-2019-2274)NessusHuawei Local Security Checks
critical
130373RHEL 7 : kernel-alt (RHSA-2019:3217)NessusRed Hat Local Security Checks
high
129519RHEL 7 : kpatch-patch (RHSA-2019:2945)NessusRed Hat Local Security Checks
high
129284SUSE SLED15 / SLES15 Security Update : kernel-source-rt (SUSE-SU-2019:2430-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (SACK Panic) (SACK Slowness) (Spectre)NessusSuSE Local Security Checks
high
129020CentOS 7 : kernel (CESA-2019:2600)NessusCentOS Local Security Checks
high
128859RHEL 8 : kernel-rt (RHSA-2019:2741)NessusRed Hat Local Security Checks
high
128845Oracle Linux 8 : kernel (ELSA-2019-2703)NessusOracle Linux Local Security Checks
high
128665RHEL 8 : kernel (RHSA-2019:2703)NessusRed Hat Local Security Checks
high
128513Oracle Linux 7 : kernel (ELSA-2019-2600)NessusOracle Linux Local Security Checks
high
128501Scientific Linux Security Update : kernel on SL7.x x86_64 (20190903)NessusScientific Linux Local Security Checks
high
128498RHEL 7 : kernel-rt (RHSA-2019:2609)NessusRed Hat Local Security Checks
high
128495RHEL 7 : kernel (RHSA-2019:2600)NessusRed Hat Local Security Checks
high
126045SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2019:1550-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (SACK Panic) (SACK Slowness) (Spectre)NessusSuSE Local Security Checks
high
126009Debian DLA-1824-1 : linux-4.9 security update (SACK Panic) (SACK Slowness)NessusDebian Local Security Checks
high
125959Debian DSA-4465-1 : linux - security update (SACK Panic) (SACK Slowness)NessusDebian Local Security Checks
high
125667openSUSE Security Update : the Linux Kernel (openSUSE-2019-1479)NessusSuSE Local Security Checks
high
125605Amazon Linux AMI : kernel (ALAS-2019-1214)NessusAmazon Linux Local Security Checks
high
125598Amazon Linux 2 : kernel (ALAS-2019-1214)NessusAmazon Linux Local Security Checks
high
125243openSUSE Security Update : the Linux Kernel (openSUSE-2019-1404) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusSuSE Local Security Checks
high
125142Ubuntu 16.04 LTS : Linux kernel (HWE) vulnerabilities (USN-3981-2) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
high
125141Ubuntu 18.04 LTS : Linux kernel vulnerabilities (USN-3981-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
high
125140Ubuntu 18.04 LTS : Linux kernel (HWE) vulnerabilities (USN-3980-2) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
high
125139Ubuntu 18.10 : Linux kernel vulnerabilities (USN-3980-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
high
125138Ubuntu 19.04 : Linux kernel vulnerabilities (USN-3979-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusUbuntu Local Security Checks
critical
125132SUSE SLES12 Security Update : kernel (SUSE-SU-2019:1242-1) (MDSUM/RIDL) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout)NessusSuSE Local Security Checks
high
124552Fedora 30 : kernel / kernel-headers / kernel-tools (2019-e84f6c34da)NessusFedora Local Security Checks
high
124308Fedora 28 : kernel / kernel-headers / kernel-tools (2019-1b986880ea)NessusFedora Local Security Checks
high
124284Fedora 29 : kernel / kernel-headers / kernel-tools (2019-1e8a4c6958)NessusFedora Local Security Checks
high