CVE-2019-15126
An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.
Published:Feb 5, 2020
Last Modified:Nov 21, 2024
EPS:Feb 5, 2020
EPSS Score:0.07993
CVSS Score:3.1
Affected Products
Vendor
Product
Action
Vendor
Apple
Product
Ipados
Apple
Ipados
Vendor
Apple
Product
Iphone Os
Apple
Iphone Os
Vendor
Apple
Product
Mac Os X
Apple
Mac Os X
Vendor
Broadcom
Product
Bcm43012
Broadcom
Bcm43012
Vendor
Broadcom
Product
Bcm43012 Firmware
Broadcom
Bcm43012 Firmware
Vendor
Broadcom
Product
Bcm43013
Broadcom
Bcm43013
Vendor
Broadcom
Product
Bcm43013 Firmware
Broadcom
Bcm43013 Firmware
Vendor
Broadcom
Product
Bcm4356
Broadcom
Bcm4356
Vendor
Broadcom
Product
Bcm4356 Firmware
Broadcom
Bcm4356 Firmware
Vendor
Broadcom
Product
Bcm4375
Broadcom
Bcm4375
Vendor
Broadcom
Product
Bcm43752
Broadcom
Bcm43752
Vendor
Broadcom
Product
Bcm43752 Firmware
Broadcom
Bcm43752 Firmware
Vendor
Broadcom
Product
Bcm4375 Firmware
Broadcom
Bcm4375 Firmware
Vendor
Broadcom
Product
Bcm4389
Broadcom
Bcm4389
Vendor
Broadcom
Product
Bcm4389 Firmware
Broadcom
Bcm4389 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
