#VU53824 Stack-based buffer overflow in RTL8170C and RTL8195AM - CVE-2020-27301

 

#VU53824 Stack-based buffer overflow in RTL8170C and RTL8195AM - CVE-2020-27301

Published: June 5, 2021 / Updated: April 21, 2022


Vulnerability identifier: #VU53824
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2020-27301
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available
Vulnerable software:
RTL8170C
RTL8195AM
Software vendor:
Realtek

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when parsing WPA2 key. A remote attacker with knowledge of network PSK can send specially crafted packets to devices connected to the WiFi network, trigger stack-based buffer overflow and execute arbitrary code on WiFi client devices.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links