{"id":31914,"date":"2019-10-31T21:43:56","date_gmt":"2019-10-31T18:43:56","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimosti-v-drajverah-k-wifi-chipam-broadcom-pozvolyayushhie-udalyonno-atakovat-sistemu\/"},"modified":"2019-10-31T21:43:56","modified_gmt":"2019-10-31T18:43:56","slug":"uyazvimosti-v-drajverah-k-wifi-chipam-broadcom-pozvolyayushhie-udalyonno-atakovat-sistemu","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-drajverah-k-wifi-chipam-broadcom-pozvolyayushhie-udalyonno-atakovat-sistemu","title":{"rendered":"Vulnerabilities in Broadcom WiFi chip drivers allow remote attacks on the system","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In the drivers for Broadcom wireless chips <noindex><a rel=\"nofollow\" href=\"https:\/\/blog.quarkslab.com\/reverse-engineering-broadcom-wireless-chipsets.html\">seven vulnerabilities have been identified<\/a><\/noindex> four <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kb.cert.org\/vuls\/id\/166939\/\">a vulnerability<\/a><\/noindex>. In the simplest case, vulnerabilities can be exploited for remote denial-of-service, but scenarios are not excluded where exploits could allow an unauthenticated attacker to execute their code with Linux kernel privileges through the sending of specially crafted packets.<\/p>\n<p>The problems were identified during the reverse engineering of Broadcom firmware. The vulnerable chips are widely used in laptops, smartphones, and various consumer devices, from Smart TVs to Internet of Things devices. In particular, Broadcom chips are used in smartphones from manufacturers such as Apple, Samsung, and Huawei. Notably, Broadcom was notified of the vulnerabilities back in September 2018, but it took about 7 months to coordinate the release of patches with hardware manufacturers.<\/p>\n<p>Two vulnerabilities affect the internal firmware and potentially allow code execution in the operating environment used in Broadcom chips, enabling attacks on environments that do not use Linux (for example, an attack on Apple devices has been confirmed, <noindex><a rel=\"nofollow\" href=\"https:\/\/support.apple.com\/en-us\/HT209600\">CVE-2019-8564<\/a><\/noindex>). It is worth noting that some Broadcom Wi-Fi chips serve as specialized processors (ARM Cortex R4 or M3), on which a semblance of their operating system runs with implementations of their wireless stack 802.11 (FullMAC). In such chips, the driver facilitates interaction between the main system and the Wi-Fi chip firmware. To gain full control over the main system after compromising FullMAC, it is recommended to use additional vulnerabilities or, on some chips, to take advantage of full access to the system memory. In chips with SoftMAC, the 802.11 wireless stack is implemented on the driver side and is executed using the system CPU.<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/blog.quarkslab.com\/resources\/2019-04-16_reversing-broadcom-wifi-chipsets\/bcm_global_stack.png\"><img decoding=\"async\" alt=\"Vulnerabilities in Broadcom WiFi chip drivers allow remote attacks on the system\" src=\"\/wp-content\/uploads\/2019\/04\/c84d863cd67388f31b82b6f71f3f273c.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Vulnerabilities in the drivers are manifested both in the proprietary wl driver (SoftMAC and FullMAC) and in the open-source brcmfmac (FullMAC). Two buffer overflows have been identified in the wl driver, exploited during the transmission of specially crafted EAPOL messages during the connection negotiation process (an attack can be carried out when connecting to a malicious access point). In the case of the SoftMAC chip, vulnerabilities lead to a compromise of the system kernel, whereas in the case of FullMAC, code can be executed on the firmware side. The brcmfmac driver has a buffer overflow and a frame processing error, which can be exploited by sending control frames. There are issues in the brcmfmac driver in the Linux kernel. <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=1b5e2423164b3670e8bc9174e4762d297990deff\">existed<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=a4176ec356c73a46c07c181c6d04039fafa34a9f\">four vulnerabilities have been fixed<\/a><\/noindex> in February.<\/p>\n<p>Identified vulnerabilities:<\/p>\n<ul>\n<li class=\"l\"> CVE-2019-9503 \u2014 incorrect behavior of the brcmfmac driver when processing control frames used for firmware interaction. If a firmware event frame comes from an external source, the driver discards it. However, if the event is received over the internal bus, the frame is passed through. The issue is that events from USB devices are transmitted over the internal bus, allowing attackers to successfully send firmware control frames when using USB interface wireless adapters.\n<li class=\"l\"> CVE-2019-9500 \u2014 enabling the 'Wake-up on Wireless LAN' feature can cause a heap overflow in the brcmfmac driver (function brcmf_wowl_nd_results) via sending a specially crafted control frame. This vulnerability can be used to execute code in the host system after compromising the chip or in combination with the CVE-2019-9503 vulnerability to bypass checks when sending a control frame remotely.\n<li class=\"l\"> CVE-2019-9501 \u2014 buffer overflow in the wl driver (function wlc_wpa_sup_eapol), occurring when processing messages with a manufacturer information field that exceeds 32 bytes.\n<li class=\"l\"> CVE-2019-9502 \u2014 buffer overflow in the wl driver (function wlc_wpa_plumb_gtk), occurring when processing messages with a manufacturer information field that exceeds 164 bytes.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50539\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445 \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0447\u0438\u043f\u043e\u0432 Broadcom \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u0447\u0435\u0442\u044b\u0440\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438. \u0412 \u043f\u0440\u043e\u0441\u0442\u0435\u0439\u0448\u0435\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043c\u043e\u0433\u0443\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u0437\u043e\u0432\u0430 \u043e\u0442\u043a\u0430\u0437\u0430 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438, \u043d\u043e \u043d\u0435 \u0438\u0441\u043a\u043b\u044e\u0447\u0430\u044e\u0442\u0441\u044f \u0438 \u0441\u0446\u0435\u043d\u0430\u0440\u0438\u0438, \u043f\u0440\u0438 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u044b \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442\u044b, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u043d\u0435\u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043a\u043e\u0434 \u0441 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u044f\u043c\u0438 \u044f\u0434\u0440\u0430 Linux \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0431\u044b\u043b\u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0432 \u0445\u043e\u0434\u0435 \u043e\u0431\u0440\u0430\u0442\u043d\u043e\u0433\u043e \u0438\u043d\u0436\u0438\u043d\u0438\u0440\u0438\u043d\u0433\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23774,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-31914","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445 \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0447\u0438\u043f\u043e\u0432 Broadcom \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u0447\u0435\u0442\u044b\u0440\u0435\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-drajverah-k-wifi-chipam-broadcom-pozvolyayushhie-udalyonno-atakovat-sistemu\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445 \u043a WiFi-\u0447\u0438\u043f\u0430\u043c Broadcom, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c \u0441\u0438\u0441\u0442\u0435\u043c\u0443 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445 \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0447\u0438\u043f\u043e\u0432 Broadcom \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u0447\u0435\u0442\u044b\u0440\u0435\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-drajverah-k-wifi-chipam-broadcom-pozvolyayushhie-udalyonno-atakovat-sistemu\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:43:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:43:56+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilities in Broadcom WiFi chip drivers allow for remote attacks on the system | ProHoster","description":"Four vulnerabilities have been identified in the drivers for Broadcom wireless chips.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-drajverah-k-wifi-chipam-broadcom-pozvolyayushhie-udalyonno-atakovat-sistemu","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445 \u043a WiFi-\u0447\u0438\u043f\u0430\u043c Broadcom, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c \u0441\u0438\u0441\u0442\u0435\u043c\u0443 | ProHoster","og:description":"\u0412 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430\u0445 \u0434\u043b\u044f \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u044b\u0445 \u0447\u0438\u043f\u043e\u0432 Broadcom \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e \u0447\u0435\u0442\u044b\u0440\u0435","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimosti-v-drajverah-k-wifi-chipam-broadcom-pozvolyayushhie-udalyonno-atakovat-sistemu","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:43:56+00:00","article:modified_time":"2019-10-31T18:43:56+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31914","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 08:25:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:08:10","updated":"2026-01-21 08:25:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31914","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=31914"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31914\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/23774"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=31914"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=31914"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=31914"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}