LOW · 3.5

CVE-2020-24586

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting t...

Vulnerability Description

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.

CVSS Score

3.5

LOW

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IeeeIeee 802.11All versions
DebianDebian Linux9.0
LinuxMac80211-
AristaC-250 Firmware< 10.0.1-31
AristaC-250-
AristaC-260 Firmware< 10.0.1-31
AristaC-260-
AristaC-230 Firmware< 10.0.1-31
AristaC-230-
AristaC-235 Firmware< 10.0.1-31
AristaC-235-
AristaC-200 Firmware< 11.0.0-36
AristaC-200-
IntelAx210 Firmware< 22.30.0.11
IntelAx210-
IntelAx201 Firmware< 22.30.0.11
IntelAx201-
IntelAx200 Firmware< 22.30.0.11
IntelAx200-
IntelAc 9560 Firmware< 22.30.0.11

References

FAQ

What is CVE-2020-24586?

CVE-2020-24586 is a vulnerability with a CVSS score of 3.5 (LOW). The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting t...

How severe is CVE-2020-24586?

CVE-2020-24586 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-24586?

Check the references section above for vendor advisories and patch information. Affected products include: Ieee Ieee 802.11, Debian Debian Linux, Linux Mac80211, Arista C-250 Firmware, Arista C-250.