MEDIUM · 6.5

CVE-2020-26141

An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An advers...

Vulnerability Description

An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
AlfaAwus036H Firmware6.1316.1209
AlfaAwus036H-
CiscoMeraki Gr10 Firmware< 27.7.1
CiscoMeraki Gr10-
CiscoMeraki Gr60 Firmware< 27.7.1
CiscoMeraki Gr60-
CiscoMeraki Mr20 Firmware< 27.7.1
CiscoMeraki Mr20-
CiscoMeraki Mr30H Firmware< 27.7.1
CiscoMeraki Mr30H-
CiscoMeraki Mr33 Firmware< 27.7.1
CiscoMeraki Mr33-
CiscoMeraki Mr36 Firmware< 27.7.1
CiscoMeraki Mr36-
CiscoMeraki Mr42 Firmware< 27.7.1
CiscoMeraki Mr42-
CiscoMeraki Mr42E Firmware< 27.7.1
CiscoMeraki Mr42E-
CiscoMeraki Mr44 Firmware< 27.7.1
CiscoMeraki Mr44-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-26141?

CVE-2020-26141 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An advers...

How severe is CVE-2020-26141?

CVE-2020-26141 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-26141?

Check the references section above for vendor advisories and patch information. Affected products include: Alfa Awus036H Firmware, Alfa Awus036H, Cisco Meraki Gr10 Firmware, Cisco Meraki Gr10, Cisco Meraki Gr60 Firmware.