LOW · 3.1

CVE-2019-15126

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper lay...

Vulnerability Description

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.

CVSS Score

3.1

LOW

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AppleIpados< 13.2
AppleIphone Os< 13.2
AppleMac Os X< 10.15.1
BroadcomBcm4389 Firmware-
BroadcomBcm4389-
BroadcomBcm43012 Firmware-
BroadcomBcm43012-
BroadcomBcm43013 Firmware-
BroadcomBcm43013-
BroadcomBcm4375 Firmware-
BroadcomBcm4375-
BroadcomBcm43752 Firmware-
BroadcomBcm43752-
BroadcomBcm4356 Firmware-
BroadcomBcm4356-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-15126?

CVE-2019-15126 is a vulnerability with a CVSS score of 3.1 (LOW). An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper lay...

How severe is CVE-2019-15126?

CVE-2019-15126 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-15126?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Ipados, Apple Iphone Os, Apple Mac Os X, Broadcom Bcm4389 Firmware, Broadcom Bcm4389.