CVE-2017-11120

CRITICAL

Broadcom Bcm4355c0 Firmware < 11.0 - Memory Corruption

Title source: rule

Description

On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an internal buffer overflow in the Wi-Fi firmware, aka B-V2017061204.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textremoteios
https://www.exploit-db.com/exploits/42784

Scores

CVSS v3 9.8
EPSS 0.2437
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (3)
apple/iphone_os < 11.0
apple/tvos < 11.0
broadcom/bcm4355c0_firmware 9.44.78.27.0.1.56
Published Sep 28, 2017
Tracked Since Feb 18, 2026