CVE-2018-19860
—CVSS 3.0
8.8 high
EPSS
1%p61
Published
()
Modified
Description
Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command.
- Vendors
- broadcomcypress
- Products
- bcm4335c0 firmware, bcm43438a1 firmware, cyw20702a1kwfbg firmware, cyw20702a1kwfbgt firmware, cyw20702b0kwfbg firmware, cyw20702b0kwfbgt firmware, cyw20703ua1kffb1g firmware, cyw20703ua1kffb1gt firmware, cyw20704ua1kffb1g firmware, cyw20704ua1kffb1gt firmware, cyw20704ua2kffb1g firmware, cyw20704ua2kffb1gt firmware
- Weakness
- CWE-732
- Vector
- CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.