#VU53825 Stack-based buffer overflow in RTL8170C and RTL8195AM - CVE-2020-27302

 

#VU53825 Stack-based buffer overflow in RTL8170C and RTL8195AM - CVE-2020-27302

Published: June 5, 2021


Vulnerability identifier: #VU53825
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-27302
CWE-ID: CWE-121
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
RTL8170C
RTL8195AM
Software vendor:
Realtek

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when parsing WPA2 key. A remote attacker with knowledge of network PSK can send specially crafted packets to devices connected to the WiFi network, trigger stack-based buffer overflow and execute arbitrary code on WiFi client devices.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links