CVE-2017-6956 describes a stack buffer overflow vulnerability in Broadcom Wi-Fi HardMAC SoCs with fbt firmware. This flaw allows for remote code execution when processing a crafted 802.11r authentication response containing an overly long R0KH-ID field within a Fast BSS Transition Information Element. Rated with a CVSS score of 8.8 (High), this vulnerability is remotely exploitable with low attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.37.34.40CPE matchmatch criteria | cpe:2.3:o:broadcom:hardmac_wi-fi_soc_firmware:6.37.34.40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.