// For flags

CVE-2020-9395

 

Severity Score

8.0
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata buffer.

Se detectó un problema en los dispositivos Realtek RTL8195AM, RTL8711AM, RTL8711AF y RTL8710AF versiones anteriores a 2.0.6. Se presenta un desbordamiento del búfer en la región stack de la memoria en el código del cliente que se encarga del protocolo de enlace de 4 vías de WPA2 por medio de un paquete EAPOL-Key malformado con un búfer de datos clave largo

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-02-25 CVE Reserved
  • 2020-07-06 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Realtek
Search vendor "Realtek"
Rtl8711af Firmware
Search vendor "Realtek" for product "Rtl8711af Firmware"
< 2.0.6
Search vendor "Realtek" for product "Rtl8711af Firmware" and version " < 2.0.6"
-
Affected
in Realtek
Search vendor "Realtek"
Rtl8711af
Search vendor "Realtek" for product "Rtl8711af"
--
Safe
Realtek
Search vendor "Realtek"
Rtl8711am Firmware
Search vendor "Realtek" for product "Rtl8711am Firmware"
< 2.0.6
Search vendor "Realtek" for product "Rtl8711am Firmware" and version " < 2.0.6"
-
Affected
in Realtek
Search vendor "Realtek"
Rtl8711am
Search vendor "Realtek" for product "Rtl8711am"
--
Safe
Realtek
Search vendor "Realtek"
Rtl8195am Firmware
Search vendor "Realtek" for product "Rtl8195am Firmware"
< 2.0.6
Search vendor "Realtek" for product "Rtl8195am Firmware" and version " < 2.0.6"
-
Affected
in Realtek
Search vendor "Realtek"
Rtl8195am
Search vendor "Realtek" for product "Rtl8195am"
--
Safe
Realtek
Search vendor "Realtek"
Rtl8710af Firmware
Search vendor "Realtek" for product "Rtl8710af Firmware"
< 2.0.6
Search vendor "Realtek" for product "Rtl8710af Firmware" and version " < 2.0.6"
-
Affected
in Realtek
Search vendor "Realtek"
Rtl8710af
Search vendor "Realtek" for product "Rtl8710af"
--
Safe