The ThreadX-based firmware on Marvell Avastar Wi-Fi devices, models 88W8787, 88W8797, 88W8801, 88W8897, and 88W8997, allows remote attackers to execute arbitrary code or cause a denial of service (block pool overflow) via malformed Wi-Fi packets during identification of available Wi-Fi networks
Published Jan 19, 2019
8.8
HIGHCVSS 3.0
EPSS 6.62%
Description
The ThreadX-based firmware on Marvell Avastar Wi-Fi devices, models 88W8787, 88W8797, 88W8801, 88W8897, and 88W8997, allows remote attackers to execute arbitrary code or cause a denial of service (block pool overflow) via malformed Wi-Fi packets during identification of available Wi-Fi networks. Exploitation of the Wi-Fi device can lead to exploitation of the host application processor in some cases, but this depends on several factors including host OS hardening and the availability of DMA.
Affected products
No data.
Configuration 1
- n/a
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- http://www.securityfocus.com/bid/106865 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://2018.zeronights.ru/wp-content/uploads/materials/19-Researching-Marvell-Avastar-Wi-Fi.pdf x_refsource_MISCExploitThird Party Advisory
- https://embedi.org/blog/remotely-compromise-devices-by-using-bugs-in-marvell-avastar-wi-fi-from-zero-knowledge-to-zero-click-rce/ x_refsource_MISCThird Party Advisory
- https://www.kb.cert.org/vuls/id/730261/ third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.scribd.com/document/398350818/WiFi-CVE-2019-6496-Marvell-s-Statement x_refsource_CONFIRMThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_07 x_refsource_CONFIRMThird Party Advisory
- https://www.zdnet.com/article/wifi-firmware-bug-affects-laptops-smartphones-routers-gaming-devices/ x_refsource_MISCExploitPress/Media CoverageThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106865 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://2018.zeronights.ru/wp-content/uploads/materials/19-Researching-Marvell-Avastar-Wi-Fi.pdf | x_refsource_MISCExploitThird Party Advisory | |
| https://embedi.org/blog/remotely-compromise-devices-by-using-bugs-in-marvell-avastar-wi-fi-from-zero-knowledge-to-zero-click-rce/ | x_refsource_MISCThird Party Advisory | |
| https://www.kb.cert.org/vuls/id/730261/ | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| https://www.scribd.com/document/398350818/WiFi-CVE-2019-6496-Marvell-s-Statement | x_refsource_CONFIRMThird Party Advisory | |
| https://www.synology.com/security/advisory/Synology_SA_19_07 | x_refsource_CONFIRMThird Party Advisory | |
| https://www.zdnet.com/article/wifi-firmware-bug-affects-laptops-smartphones-routers-gaming-devices/ | x_refsource_MISCExploitPress/Media CoverageThird Party Advisory |
Change history (0)
No recorded changes yet.