CVE-2017-11122Sensitive Information Exposure in Bcm4355c0 Firmware

Severity
7.5HIGHNVD
EPSS
1.0%
top 22.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateMay 14

Description

On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to ICMPv6 router advertisement offloading.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDbroadcom/bcm4355c0_firmware9.44.78.27.0.1.56
NVDapple/tvos10.2.2
NVDapple/iphone_os10.3.3

🔴Vulnerability Details

2
GHSA
GHSA-r6vg-fch5-hgx8: On Broadcom BCM4355C0 Wi-Fi chips 92022-05-14
CVEList
CVE-2017-11122: On Broadcom BCM4355C0 Wi-Fi chips 92017-10-04

📋Vendor Advisories

2
Apple
CVE-2017-11122: tvOS 112017-09-19
Apple
CVE-2017-11122: iOS 112017-09-19
CVE-2017-11122 — Sensitive Information Exposure | cvebase