Vulnerability Name: | CVE-2017-9417 (CCN-126974) | ||||||||||||
Assigned: | 2017-06-03 | ||||||||||||
Published: | 2017-06-03 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.6 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
8.6 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-9417 Source: FULLDISC Type: UNKNOWN 20190513 APPLE-SA-2019-5-13-6 Apple TV Software 7.3 Source: BID Type: UNKNOWN 99482 Source: CCN Type: BID-99482 Google Android Broadcom components Multiple Security Vulnerabilities Source: SECTRACK Type: UNKNOWN 1038950 Source: SECTRACK Type: UNKNOWN 1039330 Source: XF Type: UNKNOWN broadcom-cve20179417-code-exec(126974) Source: MLIST Type: UNKNOWN [debian-lts-announce] 20181113 [SECURITY] [DLA 1573-1] firmware-nonfree security update Source: CCN Type: Microsoft Security TechCenter - September 2017 Broadcom BCM43xx Remote Code Execution Vulnerability Source: CONFIRM Type: UNKNOWN https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-9417 Source: BUGTRAQ Type: UNKNOWN 20190514 APPLE-SA-2019-5-13-6 Apple TV Software 7.3 Source: CONFIRM Type: UNKNOWN https://source.android.com/security/bulletin/2017-07-01 Source: CCN Type: Apple security document HT207922 About the security content of macOS Sierra 10.12.6, Security Update 2017-003 El Capitan, and Security Update 2017-003 Yosemite Source: CCN Type: Apple security document HT207923 About the security content of iOS 10.3.3 Source: CCN Type: Apple security document HT207924 About the security content of tvOS 10.2.2 Source: CCN Type: Apple security document HT207925 About the security content of watchOS 3.2.3 Source: CCN Type: Apple security document HT207940 About the security content of Wi-Fi Update for Boot Camp 6.1 Source: CCN Type: Apple security document HT208354 About the security content of AirPort Base Station Firmware Update 7.7.9 Source: CCN Type: Apple security document HT210121 About the security content of Apple TV Software 7.3 Source: CONFIRM Type: UNKNOWN https://support.apple.com/kb/HT210121 Source: CCN Type: Black Hat Web site Broadpwn: Remotely Compromising Android and iOS via a Bug in Broadcom's Wi-Fi Chipsets Source: MISC Type: Technical Description, Third Party Advisory https://www.blackhat.com/us-17/briefings.html#broadpwn-remotely-compromising-android-and-ios-via-a-bug-in-broadcoms-wi-fi-chipsets Source: CCN Type: Broadcom Web site BCM43xx Wi-Fi chips | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |