Vulnerability Description
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra" attack.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2052676
- https://github.com/RPi-Distro/bluez-firmware/commit/8445a53ce2c51a77472b908a0c8f
- https://www.informatik.tu-darmstadt.de/fb20/aktuelles_fb20/fb20_neuigkeiten/neui
- https://www.informatik.tu-darmstadt.de/seemoo/team_seemoo/jiska_classen/index.en
FAQ
What is CVE-2020-10367?
CVE-2020-10367 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra" attack.
How severe is CVE-2020-10367?
CVE-2020-10367 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10367?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.