CVE-2019-6496
PoC ×2—CVSS 3.0
8.8 high
EPSS
7%p93
Published
()
Modified
Description
The ThreadX-based firmware on Marvell Avastar Wi-Fi devices, models 88W8787, 88W8797, 88W8801, 88W8897, and 88W8997, allows remote attackers to execute arbitrary code or cause a denial of service (block pool overflow) via malformed Wi-Fi packets during identification of available Wi-Fi networks. Exploitation of the Wi-Fi device can lead to exploitation of the host application processor in some cases, but this depends on several factors including host OS hardening and the availability of DMA.
- Vendors
- marvell
- Products
- 88w8787 firmware, 88w8797 firmware, 88w8801 firmware, 88w8897 firmware, 88w8997 firmware
- Weakness
- CWE-787
- Vector
- CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.