Stack-based buffer overflow in RTL8170C and RTL8195AM - CVE-2020-27301

 

Stack-based buffer overflow in RTL8170C and RTL8195AM - CVE-2020-27301

Published: June 5, 2021 / Updated: April 21, 2022


Vulnerability identifier: #VU53824
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27301
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when parsing WPA2 key. A remote attacker with knowledge of network PSK can send specially crafted packets to devices connected to the WiFi network, trigger stack-based buffer overflow and execute arbitrary code on WiFi client devices.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

RTL8170C
RTL8195AM

How to mitigate CVE-2020-27301

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins