Lucene search

K
cveVDOOCVE-2020-27302
HistoryJun 04, 2021 - 1:15 p.m.

CVE-2020-27302

2021-06-0413:15:08
CWE-787
VDOO
web.nvd.nist.gov
53
6
security
vulnerability
cve-2020-27302
realtek rtl8710
ameba-based devices
wi-fi
wpa2
buffer overflow
remote code execution
nvd

CVSS2

7.7

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

34.6%

A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the “memcpy” function, when an attacker in Wi-Fi range sends a crafted “Encrypted GTK” value as part of the WPA2 4-way-handshake.

Affected configurations

Nvd
Node
realtekrtl8710c_firmwareMatch-
AND
realtekrtl8710cMatch-
Node
realtekrtl8195a_firmwareMatch-
AND
realtekrtl8195aMatch-
VendorProductVersionCPE
realtekrtl8710c_firmware-cpe:2.3:o:realtek:rtl8710c_firmware:-:*:*:*:*:*:*:*
realtekrtl8710c-cpe:2.3:h:realtek:rtl8710c:-:*:*:*:*:*:*:*
realtekrtl8195a_firmware-cpe:2.3:o:realtek:rtl8195a_firmware:-:*:*:*:*:*:*:*
realtekrtl8195a-cpe:2.3:h:realtek:rtl8195a:-:*:*:*:*:*:*:*

Social References

More

CVSS2

7.7

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

34.6%

Related for CVE-2020-27302