peter bassill · operator
$ cve CVE-2019-15126 JSON

CVE-2019-15126 EXPLOIT

3.1
LOW · CVSS 3.1 · EPSS 7.3% (pctl 94)

Patch early

A public exploit exists.

Description

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.

Scoring

CVSS3.1 (LOW, v3.1)
VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS7.26% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-367
On CISA KEVno
Public exploityes
Published2020-02-05
Last modified2026-06-17

Affected (15)

VendorProduct
appleipados
appleiphone os
applemac os x
broadcombcm43012
broadcombcm43012 firmware
broadcombcm43013
broadcombcm43013 firmware
broadcombcm4356
broadcombcm4356 firmware
broadcombcm4375
broadcombcm4375 firmware
broadcombcm43752
broadcombcm43752 firmware
broadcombcm4389
broadcombcm4389 firmware

Public exploits

SourceTitleDate
exploit-dbBroadcom Wi-Fi Devices - 'KR00K Information Disclosure2020-03-18

References

→ the Explorer  ·  watch your stack  ·  NVD