CVE-2020-24586
3.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.1 / Impact: 1.4
Source: NVD
Description
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.
Affected (30)
Show all products
Ieee: Ieee 802.11 · Debian: Debian Linux · Linux: Mac80211, Linux Kernel · Arista: C 250 Firmware, C 260 Firmware, C 230 Firmware, C 235 Firmware, C 200 Firmware · Intel: Ax210 Firmware, Ax201 Firmware, Ax200 Firmware, Ac 9560 Firmware, Ac 9462 Firmware, Ac 9461 Firmware, Ac 9260 Firmware, Ac 8265 Firmware, Ac 8260 Firmware, Ac 3168 Firmware, Ac 7265 Firmware, Ac 3165 Firmware, Ax1675 Firmware, Ax1650 Firmware, Ac 1550 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.1-31 |
| Running on/with | Platform Versions |
|---|---|
Arista C 250 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.1-31 |
| Running on/with | Platform Versions |
|---|---|
Arista C 260 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.1-31 |
| Running on/with | Platform Versions |
|---|---|
Arista C 230 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.1-31 |
| Running on/with | Platform Versions |
|---|---|
Arista C 235 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.0.0-36 |
| Running on/with | Platform Versions |
|---|---|
Arista C 200 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 22.30.0.11 |
| Running on/with | Platform Versions |
|---|---|
Intel Ax210 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 22.30.0.11 |
| Running on/with | Platform Versions |
|---|---|
Intel Ax201 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 22.30.0.11 |
| Running on/with | Platform Versions |
|---|---|
Intel Ax200 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 22.30.0.11 |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 9560 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 22.30.0.11 |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 9462 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 22.30.0.11 |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 9461 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 22.30.0.11 |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 9260 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 20.70.21.2 |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 8265 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 20.70.21.2 |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 8260 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 19.51.33.1 |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 3168 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 19.51.33.1 |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 7265 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 19.51.33.1 |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 3165 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Intel Ax1675 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Intel Ax1650 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Intel Ac 1550 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.14 to 4.14.235 |
References (18)
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.