CVE-2017-0561
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 29.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the context of the Wi-Fi SoC. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34199105. References: B-RB#110814.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 29.82% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- linux/linux kernel
- Source
- security@android.com
References
- http://www.securityfocus.com/bid/97367Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038201
- https://lists.debian.org/debian-lts-announce/2018/11/msg00015.html
- https://source.android.com/security/bulletin/2017-04-01Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/41805/
- https://www.exploit-db.com/exploits/41806/
- http://www.securityfocus.com/bid/97367Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038201
- https://lists.debian.org/debian-lts-announce/2018/11/msg00015.html
- https://source.android.com/security/bulletin/2017-04-01Patch, Vendor Advisory
- https://www.exploit-db.com/exploits/41805/
- https://www.exploit-db.com/exploits/41806/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.