CVE-2020-24586
published 2021-05-11CVE-2020-24586: The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be…
low3.5CVSS 3.1
AVAACLPRNUIRSUCLINAN
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | c-200_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-230_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | c-235_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | c-250_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | c-260_firmware | < 10.0.1-31 | 10.0.1-31 |
| debian | debian_linux | — | — |
| debian | firmware-nonfree | < firmware-nonfree 20210818-1 (bookworm) | firmware-nonfree 20210818-1 (bookworm) |
| debian | linux | < firmware-nonfree 20210818-1 (bookworm) | firmware-nonfree 20210818-1 (bookworm) |
| intel | ac_3165_firmware | < 19.51.33.1 | 19.51.33.1 |
| intel | ac_3168_firmware | < 19.51.33.1 | 19.51.33.1 |
| intel | ac_7265_firmware | < 19.51.33.1 | 19.51.33.1 |
| intel | ac_8260_firmware | < 20.70.21.2 | 20.70.21.2 |
| intel | ac_8265_firmware | < 20.70.21.2 | 20.70.21.2 |
| intel | ac_9260_firmware | < 22.30.0.11 | 22.30.0.11 |
| intel | ac_9461_firmware | < 22.30.0.11 | 22.30.0.11 |
| intel | ac_9462_firmware | < 22.30.0.11 | 22.30.0.11 |
| intel | ac_9560_firmware | < 22.30.0.11 | 22.30.0.11 |
| intel | ax200_firmware | < 22.30.0.11 | 22.30.0.11 |
| intel | ax201_firmware | < 22.30.0.11 | 22.30.0.11 |
| intel | ax210_firmware | < 22.30.0.11 | 22.30.0.11 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 4.15.0-151.157 | 4.15.0-151.157 |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv3.5LOW