3.5

CVE-2020-24586

Exploit
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 9.0
Linux ≫ Mac80211 Version -
Arista ≫ C-250 Firmware Version < 10.0.1-31
   Arista ≫ C-250 Version -
Arista ≫ C-260 Firmware Version < 10.0.1-31
   Arista ≫ C-260 Version -
Arista ≫ C-230 Firmware Version < 10.0.1-31
   Arista ≫ C-230 Version -
Arista ≫ C-235 Firmware Version < 10.0.1-31
   Arista ≫ C-235 Version -
Arista ≫ C-200 Firmware Version < 11.0.0-36
   Arista ≫ C-200 Version -
Intel ≫ Ax210 Firmware Version < 22.30.0.11
   Intel ≫ Ax210 Version -
Intel ≫ Ax201 Firmware Version < 22.30.0.11
   Intel ≫ Ax201 Version -
Intel ≫ Ax200 Firmware Version < 22.30.0.11
   Intel ≫ Ax200 Version -
Intel ≫ Ac 9560 Firmware Version < 22.30.0.11
   Intel ≫ Ac 9560 Version -
Intel ≫ Ac 9462 Firmware Version < 22.30.0.11
   Intel ≫ Ac 9462 Version -
Intel ≫ Ac 9461 Firmware Version < 22.30.0.11
   Intel ≫ Ac 9461 Version -
Intel ≫ Ac 9260 Firmware Version < 22.30.0.11
   Intel ≫ Ac 9260 Version -
Intel ≫ Ac 8265 Firmware Version < 20.70.21.2
   Intel ≫ Ac 8265 Version -
Intel ≫ Ac 8260 Firmware Version < 20.70.21.2
   Intel ≫ Ac 8260 Version -
Intel ≫ Ac 3168 Firmware Version < 19.51.33.1
   Intel ≫ Ac 3168 Version -
Intel ≫ Ac 7265 Firmware Version < 19.51.33.1
   Intel ≫ Ac 7265 Version -
Intel ≫ Ac 3165 Firmware Version < 19.51.33.1
   Intel ≫ Ac 3165 Version -
Intel ≫ Ax1675 Firmware Version -
   Intel ≫ Ax1675 Version -
Intel ≫ Ax1650 Firmware Version -
   Intel ≫ Ax1650 Version -
Intel ≫ Ac 1550 Firmware Version -
   Intel ≫ Ac 1550 Version -
Linux ≫ Linux Kernel Version >= 4.4 < 4.4.271
Linux ≫ Linux Kernel Version >= 4.9 < 4.9.271
Linux ≫ Linux Kernel Version >= 4.14 < 4.14.235
Linux ≫ Linux Kernel Version >= 4.19 < 4.19.193
Linux ≫ Linux Kernel Version >= 5.4 < 5.4.124
Linux ≫ Linux Kernel Version >= 5.10 < 5.10.42
Linux ≫ Linux Kernel Version >= 5.12 < 5.12.9
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.77% 0.921
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.5 2.1 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
NIST 2.9 5.5 2.9
AV:A/AC:M/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2023/04/msg00002.html
http://www.openwall.com/lists/oss-security/2021/05/11/12
Third Party Advisory
Mailing List
https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md
Third Party Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu
Third Party Advisory
https://www.fragattacks.com
Third Party Advisory
Exploit
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00473.html
Third Party Advisory