CVE Feed

    Dashboard / CVE / CVE-2020-24586

    CVE-2020-24586

    The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.

    Published:May 11, 2021
    Last Modified:Nov 21, 2024
    EPS:May 11, 2021
    EPSS Score:0.00254
    CVSS Score:3.5

    Affected Products

    Vendor
    Arista
    Product
    C-200
    Vendor
    Arista
    Product
    C-200 Firmware
    Vendor
    Arista
    Product
    C-230
    Vendor
    Arista
    Product
    C-230 Firmware
    Vendor
    Arista
    Product
    C-235
    Vendor
    Arista
    Product
    C-235 Firmware
    Vendor
    Arista
    Product
    C-250
    Vendor
    Arista
    Product
    C-250 Firmware
    Vendor
    Arista
    Product
    C-260
    Vendor
    Arista
    Product
    C-260 Firmware
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Ieee
    Product
    Ieee 802.11
    Vendor
    Intel
    Product
    Ac 1550
    Vendor
    Intel
    Product
    Ac 1550 Firmware
    Vendor
    Intel
    Product
    Ac 3165
    Vendor
    Intel
    Product
    Ac 3165 Firmware
    Vendor
    Intel
    Product
    Ac 3168
    Vendor
    Intel
    Product
    Ac 3168 Firmware
    Vendor
    Intel
    Product
    Ac 7265
    Vendor
    Intel
    Product
    Ac 7265 Firmware
    Vendor
    Intel
    Product
    Ac 8260
    Vendor
    Intel
    Product
    Ac 8260 Firmware
    Vendor
    Intel
    Product
    Ac 8265
    Vendor
    Intel
    Product
    Ac 8265 Firmware
    Vendor
    Intel
    Product
    Ac 9260
    Vendor
    Intel
    Product
    Ac 9260 Firmware
    Vendor
    Intel
    Product
    Ac 9461
    Vendor
    Intel
    Product
    Ac 9461 Firmware
    Vendor
    Intel
    Product
    Ac 9462
    Vendor
    Intel
    Product
    Ac 9462 Firmware
    Vendor
    Intel
    Product
    Ac 9560
    Vendor
    Intel
    Product
    Ac 9560 Firmware
    Vendor
    Intel
    Product
    Ax1650
    Vendor
    Intel
    Product
    Ax1650 Firmware
    Vendor
    Intel
    Product
    Ax1675
    Vendor
    Intel
    Product
    Ax1675 Firmware
    Vendor
    Intel
    Product
    Ax200
    Vendor
    Intel
    Product
    Ax200 Firmware
    Vendor
    Intel
    Product
    Ax201
    Vendor
    Intel
    Product
    Ax201 Firmware
    Vendor
    Intel
    Product
    Ax210
    Vendor
    Intel
    Product
    Ax210 Firmware
    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Linux
    Product
    Mac80211
    Vendor
    Redhat
    Product
    Enterprise Linux

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High