First published: Mon Mar 27 2017(Updated: )
Stack-based buffer overflow in the firmware in Broadcom Wi-Fi HardMAC SoC chips, when the firmware supports CCKM Fast and Secure Roaming and the feature is enabled in RAM, allows remote attackers to execute arbitrary code via a crafted reassociation response frame with a Cisco IE (156).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Bcm4339 Firmware | =6.37.34.40 | |
Broadcom Bcm4339 Soc Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6957 is classified as a critical vulnerability due to the potential for remote code execution.
To remediate CVE-2017-6957, update the firmware of the affected Broadcom Wi-Fi HardMAC SoC chips to the latest version that addresses this vulnerability.
CVE-2017-6957 primarily affects devices using Broadcom BCM4339 SOC firmware version 6.37.34.40 that support CCKM Fast and Secure Roaming.
Yes, CVE-2017-6957 can be exploited remotely by attackers via a crafted reassociation response frame.
Exploitation of CVE-2017-6957 can lead to arbitrary code execution on the affected devices.