CVE-2020-24586
Vulnerability Summary
Timeline
Description
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.
CVSS Metrics
- v3.1•LOW•Score: 3.5CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- v2.0•LOW•Score: 2.9AV:A/AC:M/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 5.76%• Percentile: 93%
Affected Systems
- arista•c-200_firmware
< 11.0.0-36
- arista•c-230_firmware
< 10.0.1-31
- arista•c-235_firmware
< 10.0.1-31
- arista•c-250_firmware
< 10.0.1-31
- arista•c-260_firmware
< 10.0.1-31
- debian•firmware-nonfree
all | < 20210818-1 | < 20210818-1 | < 20210818-1
- debian•linux
< 5.10.46-1 | < 5.10.46-1 | < 5.10.46-1 | < 5.10.46-1
- ubuntu•linux
all | < 4.15.0-151.157 | < 5.4.0-77.86
- ubuntu•linux-aws
all | < 4.15.0-1109.116 | < 5.4.0-1051.53
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1051.53~18.04.1
- ubuntu•linux-aws-5.8
< 5.8.0-1038.40~20.04.1
- ubuntu•linux-aws-fips
< 4.15.0-2051.53 | all | < 5.4.0-1069.73+fips2
- ubuntu•linux-aws-hwe
< 4.15.0-1109.116~16.04.1
- ubuntu•linux-azure
< 4.15.0-1121.134~14.04.1 | < 4.15.0-1121.134~16.04.1 | all | < 5.4.0-1051.53
- ubuntu•linux-azure-4.15
< 4.15.0-1121.134
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1051.53~18.04.1
- ubuntu•linux-azure-5.8
< 5.8.0-1036.38~20.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde-5.15
< 5.15.0-1114.123~20.04.1
- ubuntu•linux-azure-fips
< 4.15.0-2033.37 | all | < 5.4.0-1073.76+fips1
- ubuntu•linux-bluefield
all | < 5.4.0-1013.16
- ubuntu•linux-dell300x
< 4.15.0-1027.32
- ubuntu•linux-fips
all | < 4.15.0-1066.75 | < 5.4.0-1028.32
- ubuntu•linux-gcp
< 4.15.0-1106.120~16.04.1 | all | < 5.4.0-1046.49
- ubuntu•linux-gcp-4.15
< 4.15.0-1106.120
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1046.49~18.04.1
- ubuntu•linux-gcp-5.8
< 5.8.0-1035.37~20.04.1
- ubuntu•linux-gcp-edge
all
- ubuntu•linux-gcp-fips
< 4.15.0-2016.18 | all | < 5.4.0-1067.71~20.04.1
- ubuntu•linux-gke
< 5.4.0-1046.48
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.4
< 5.4.0-1046.48~18.04.1
- ubuntu•linux-gkeop
< 5.4.0-1018.19
- ubuntu•linux-gkeop-5.4
< 5.4.0-1018.19~18.04.1
- ubuntu•linux-hwe
< 4.15.0-151.157~16.04.1 | all
- ubuntu•linux-hwe-5.4
< 5.4.0-77.86~18.04.1
- ubuntu•linux-hwe-5.8
< 5.8.0-59.66~20.04.1
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
all | < 4.15.0-1097.99 | < 5.4.0-1041.42
- ubuntu•linux-lts-xenial
all
- ubuntu•linux-oem
all
- ubuntu•linux-oem-5.10
< 5.10.0-1032.33
- ubuntu•linux-oem-5.6
all
- ubuntu•linux-oracle
< 4.15.0-1078.86~16.04.1 | < 4.15.0-1078.86 | < 5.4.0-1048.52
- ubuntu•linux-oracle-5.0
all
Showing first 50 affected entries in server-rendered view.
References (20)
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00473.html
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu
- https://www.fragattacks.com
- https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md
- http://www.openwall.com/lists/oss-security/2021/05/11/12
- https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html
- https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html
- https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63
- https://lists.debian.org/debian-lts-announce/2023/04/msg00002.html
- https://ubuntu.com/security/CVE-2020-24586
- https://papers.mathyvanhoef.com/usenix2021.pdf
- https://ubuntu.com/security/notices/USN-4997-1
- https://ubuntu.com/security/notices/USN-4999-1
- https://ubuntu.com/security/notices/USN-5000-1
- https://ubuntu.com/security/notices/USN-5001-1
- https://ubuntu.com/security/notices/USN-5018-1
- https://ubuntu.com/security/notices/USN-5000-2
- https://ubuntu.com/security/notices/USN-4997-2
- https://www.cve.org/CVERecord?id=CVE-2020-24586
- https://security-tracker.debian.org/tracker/CVE-2020-24586