CVE-2018-19860

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/06/2019
Last modified:
24/08/2020

Description

Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:broadcom:bcm4335c0_firmware:2012-12-11:*:*:*:*:*:*:*
cpe:2.3:h:broadcom:bcm4335c0:-:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:bcm43438a1_firmware:2014-06-02:*:*:*:*:*:*:*
cpe:2.3:h:broadcom:bcm43438a1:-:*:*:*:*:*:*:*
cpe:2.3:o:cypress:cyw20702a1kwfbg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cypress:cyw20702a1kwfbg:-:*:*:*:*:*:*:*
cpe:2.3:o:cypress:cyw20702a1kwfbgt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cypress:cyw20702a1kwfbgt:-:*:*:*:*:*:*:*
cpe:2.3:o:cypress:cyw20702b0kwfbg_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cypress:cyw20702b0kwfbg:-:*:*:*:*:*:*:*
cpe:2.3:o:cypress:cyw20702b0kwfbgt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cypress:cyw20702b0kwfbgt:-:*:*:*:*:*:*:*
cpe:2.3:o:cypress:cyw20703ua1kffb1g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:cypress:cyw20703ua1kffb1g:-:*:*:*:*:*:*:*
cpe:2.3:o:cypress:cyw20703ua1kffb1gt_firmware:-:*:*:*:*:*:*:*