Learn about CVE-2017-11122, a vulnerability in Broadcom BCM4355C0 Wi-Fi chips with firmware version 9.44.78.27.0.1.56, allowing attackers to leak information via ICMPv6 router advertisement offloading.
CVE-2017-11122 was published on October 4, 2017, and involves an information leak vulnerability in Broadcom BCM4355C0 Wi-Fi chips with firmware version 9.44.78.27.0.1.56. Attackers can exploit the ICMPv6 router advertisement offloading feature to trigger this vulnerability.
Understanding CVE-2017-11122
This CVE entry highlights a specific security issue related to insufficient length validation on Broadcom Wi-Fi chips, potentially leading to information disclosure.
What is CVE-2017-11122?
The vulnerability in Broadcom BCM4355C0 Wi-Fi chips with firmware version 9.44.78.27.0.1.56 allows attackers to leak information by exploiting the ICMPv6 router advertisement offloading feature.
The Impact of CVE-2017-11122
The vulnerability can result in an information leak, potentially exposing sensitive data to unauthorized parties.
Technical Details of CVE-2017-11122
This section delves into the technical aspects of the CVE entry.
Vulnerability Description
The vulnerability arises from insufficient length validation on Broadcom BCM4355C0 Wi-Fi chips with firmware version 9.44.78.27.0.1.56, enabling attackers to trigger an information leak through the ICMPv6 router advertisement offloading feature.
Affected Systems and Versions
Exploitation Mechanism
Attackers exploit the ICMPv6 router advertisement offloading feature on Broadcom BCM4355C0 Wi-Fi chips with the specified firmware version to trigger the information leak vulnerability.
Mitigation and Prevention
Protecting systems from CVE-2017-11122 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates