MEDIUM · 6.5

CVE-2020-26143

An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adver...

Vulnerability Description

An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
AlfaAwus036H Firmware1030.36.604
AlfaAwus036H-
AristaC-75 Firmware-
AristaC-75-
AristaO-90 Firmware-
AristaO-90-
AristaC-65 Firmware-
AristaC-65-
AristaW-68 Firmware-
AristaW-68-
SiemensScalance W700 Ieee 802.11N FirmwareAll versions
SiemensScalance W700 Ieee 802.11N-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-26143?

CVE-2020-26143 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adver...

How severe is CVE-2020-26143?

CVE-2020-26143 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-26143?

Check the references section above for vendor advisories and patch information. Affected products include: Alfa Awus036H Firmware, Alfa Awus036H, Arista C-75 Firmware, Arista C-75, Arista O-90 Firmware.