CVE-2019-9500 describes a heap buffer overflow vulnerability in the Broadcom brcmfmac WiFi driver, affecting Linux kernels and Broadcom's brcmfmac_driver. This flaw, triggered by specially crafted WiFi packets when Wake-up on Wireless LAN is enabled, allows a remote, unauthenticated attacker to potentially execute arbitrary code or cause denial-of-service. With a CVSS score of 8.3 (High), it presents a significant risk due to its adjacent network attack vector and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:broadcom:brcmfmac_driver:-:*:*:*:*:*:*:* | ||
>= 4.5, < 4.9.181CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.123CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.47CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.0.20CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.