An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.
CVSS Details
- CVSS 3.1 Base Score: 3.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Wifi | apple-osx-security-update-2019-002-mojaveapple-osx-security-update-2019-007-high-sierraapple-osx-upgrade-latest | Feb 12, 2020 | Feb 5, 2020 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Feb 5, 2020 | |
| Suse | — | suse-upgrade-cluster-md-kmp-defaultsuse-upgrade-dlm-kmp-defaultsuse-upgrade-gfs2-kmp-defaultsuse-upgrade-kernel-debug-basesuse-upgrade-kernel-defaultsuse-upgrade-kernel-default-extrasuse-upgrade-kernel-default-mansuse-upgrade-kernel-docssuse-upgrade-kernel-firmwaresuse-upgrade-kernel-kvmsmall-basesuse-upgrade-kernel-obs-buildsuse-upgrade-kernel-vanillasuse-upgrade-kernel-vanilla-basesuse-upgrade-kernel-vanilla-develsuse-upgrade-kernel-vanilla-livepatch-develsuse-upgrade-kernel-zfcpdump-mansuse-upgrade-ocfs2-kmp-defaultsuse-upgrade-ucode-amd | Dec 14, 2021 | Feb 5, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub