4 ms·
Probably not all BCM43xx devices are affected, though. This product line spans over 10 years and all 802.11 revisions since a/b with various firmwares and inter
by qb45 9y ago
Probably not all BCM43xx devices are affected, though. This product line spans over 10 years and all 802.11 revisions since a/b with various firmwares and internal CPUs, from custom cores to ARM.
The issue likely exists in a limited number of chips, possibly only FullMAC ones, like similar bug found earlier by Google:
https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html https://googleprojectzero.blogspot.com/2017/04/over-air-expl...
edit:
Actually NIST lists the vulnerable NICs: BCM4354, BCM4358, BCM4359.
- osivertsson 9y agoNIST's list is incomplete, at least BCM43570 is vulnerable as well [1]. I would expect many more Broadcom chips to be vulnerable even if exploits may need to be tweaked. [1] I'm part of a team that develops a product with this chip, and I've used the hostapd configuration I linked elsewhere in this topic to show it is vulnerable.