CVE-2019-6496
Last modified
CVE-2019-6496 is a vulnerability of currently unknown severity. The ThreadX-based firmware on Marvell Avastar Wi-Fi devices, models 88W8787, 88W8797, 88W8801, 88W8897, and 88W8997, allows remote attackers to execute arbitrary code or cause a denial of service (block pool overflow) via malformed Wi-Fi packets during identification of available Wi-Fi networks. Exploitation of the Wi-Fi device can lead to exploitation of the host application processor in some cases, but this depends on several factors including host OS hardening and the availability of DMA.. EPSS estimates a 6.62% chance of exploitation in the next 30 days.
Description
The ThreadX-based firmware on Marvell Avastar Wi-Fi devices, models 88W8787, 88W8797, 88W8801, 88W8897, and 88W8997, allows remote attackers to execute arbitrary code or cause a denial of service (block pool overflow) via malformed Wi-Fi packets during identification of available Wi-Fi networks. Exploitation of the Wi-Fi device can lead to exploitation of the host application processor in some cases, but this depends on several factors including host OS hardening and the availability of DMA.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Marvell | 88w8787 Firmware | All versions |
| Marvell | 88w8797 Firmware | All versions |
| Marvell | 88w8801 Firmware | All versions |
| Marvell | 88w8897 Firmware | All versions |
| Marvell | 88w8997 Firmware | All versions |
References
- http://www.securityfocus.com/bid/106865Third Party Advisory, VDB Entry
- https://2018.zeronights.ru/wp-content/uploads/materials/19-Researching-Marvell-Avastar-Wi-Fi.pdfExploit, Third Party Advisory
- https://www.kb.cert.org/vuls/id/730261/Third Party Advisory, US Government Resource
- https://www.scribd.com/document/398350818/WiFi-CVE-2019-6496-Marvell-s-StatementThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_07Third Party Advisory
- https://www.zdnet.com/article/wifi-firmware-bug-affects-laptops-smartphones-routers-gaming-devices/Exploit, Press/Media Coverage, Third Party Advisory
- http://www.securityfocus.com/bid/106865Third Party Advisory, VDB Entry
- https://2018.zeronights.ru/wp-content/uploads/materials/19-Researching-Marvell-Avastar-Wi-Fi.pdfExploit, Third Party Advisory
- https://www.kb.cert.org/vuls/id/730261/Third Party Advisory, US Government Resource
- https://www.scribd.com/document/398350818/WiFi-CVE-2019-6496-Marvell-s-StatementThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_07Third Party Advisory
- https://www.zdnet.com/article/wifi-firmware-bug-affects-laptops-smartphones-routers-gaming-devices/Exploit, Press/Media Coverage, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6496?
How severe is CVE-2019-6496?
How do I fix CVE-2019-6496?
Are you affected by CVE-2019-6496?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
