{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-02T23:45:28.868","vulnerabilities":[{"cve":{"id":"CVE-2019-9500","sourceIdentifier":"cret@cert.org","published":"2020-01-16T21:15:12.007","lastModified":"2024-11-21T04:51:44.480","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions."},{"lang":"es","value":"El controlador Broadcom brcmfmac WiFi antes de commit 1b5e2423164b3670e8bc9174e4762d297990deff, es vulnerable a un desbordamiento del búfer de la pila. Si es configurada la funcionalidad Wake-up on Wireless LAN, una trama de evento malicioso puede ser construida para desencadenar un desbordamiento del búfer de la pila en la función brcmf_wowl_nd_results. Esta vulnerabilidad puede ser explotada con chipsets comprometidos para comprometer el host, o cuando es usada en combinación con CVE-2019-9503, puede ser usada remotamente. En el peor de los casos, mediante el envío de paquetes WiFi especialmente diseñados, un atacante remoto no autenticado puede ejecutar código arbitrario sobre un sistema vulnerable. Más típicamente, esta vulnerabilidad resultará en condiciones de denegación de servicio."}],"metrics":{"cvssMetricV31":[{"source":"cret@cert.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":7.9,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":6.0}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:M/Au:N/C:C/I:C/A:C","baseScore":7.9,"accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":5.5,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cret@cert.org","type":"Secondary","description":[{"lang":"en","value":"CWE-122"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:broadcom:brcmfmac_driver:-:*:*:*:*:*:*:*","matchCriteriaId":"E300306D-8929-403F-BF11-AB86A3414EA1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.5","versionEndExcluding":"4.9.181","matchCriteriaId":"26A52A04-54E8-4081-ABFD-F3F78CFE91D0"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"4.14.123","matchCriteriaId":"963FBC10-799B-4E56-B7FC-D260394C77CC"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15","versionEndExcluding":"4.19.47","matchCriteriaId":"BDFB304D-9D53-4328-ADF8-A05CC880C555"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.20","versionEndExcluding":"5.0.20","matchCriteriaId":"F332F557-E7B3-45BB-A03F-0CCF2C6F7987"}]}]}],"references":[{"url":"https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html","source":"cret@cert.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff","source":"cret@cert.org","tags":["Patch","Third Party Advisory"]},{"url":"https://kb.cert.org/vuls/id/166939/","source":"cret@cert.org","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://git.kernel.org/linus/1b5e2423164b3670e8bc9174e4762d297990deff","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://kb.cert.org/vuls/id/166939/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]}]}}]}