An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata buffer.
References
Link | Resource |
---|---|
https://github.com/ambiot/amb1_arduino/commit/dcea55cf9775a0166805b3db845b237ecd5e74ea#diff-d06e7a87f34cc464a56799a419033014 | Patch Third Party Advisory |
https://github.com/ambiot/amb1_sdk/commit/bc5173d5d4faf6829074b0f1e1b242c12b7777a3#diff-700c216fb376666eaeda0c892e8bdc09 | Patch Third Party Advisory |
https://www.amebaiot.com/en/security_bulletin/ | Third Party Advisory |
https://github.com/ambiot/amb1_arduino/commit/dcea55cf9775a0166805b3db845b237ecd5e74ea#diff-d06e7a87f34cc464a56799a419033014 | Patch Third Party Advisory |
https://github.com/ambiot/amb1_sdk/commit/bc5173d5d4faf6829074b0f1e1b242c12b7777a3#diff-700c216fb376666eaeda0c892e8bdc09 | Patch Third Party Advisory |
https://www.amebaiot.com/en/security_bulletin/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 05:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ambiot/amb1_arduino/commit/dcea55cf9775a0166805b3db845b237ecd5e74ea#diff-d06e7a87f34cc464a56799a419033014 - Patch, Third Party Advisory | |
References | () https://github.com/ambiot/amb1_sdk/commit/bc5173d5d4faf6829074b0f1e1b242c12b7777a3#diff-700c216fb376666eaeda0c892e8bdc09 - Patch, Third Party Advisory | |
References | () https://www.amebaiot.com/en/security_bulletin/ - Third Party Advisory |
Information
Published : 2020-07-06 22:15
Updated : 2024-11-21 05:40
NVD link : CVE-2020-9395
Mitre link : CVE-2020-9395
CVE.ORG link : CVE-2020-9395
JSON object : View
Products Affected
realtek
- rtl8711am_firmware
- rtl8711af
- rtl8711af_firmware
- rtl8195am_firmware
- rtl8195am
- rtl8710af_firmware
- rtl8710af
- rtl8711am
CWE
CWE-787
Out-of-bounds Write