CVE-2020-24586

Aliases:UBUNTU-CVE-2020-24586DEBIAN-CVE-2020-24586
Advisory lineage Upstream: 0 Downstream: 35
Modified
Published: 11 May 2021, 00:00
Last modified:04 Aug 2024, 15:19

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
3.5 LOW
v3.1 (nvd)
EPSS Score
5.76% LOW
6% probability +5.23%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

11 May 2021, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 15:19
Last Modified
Vulnerability information updated

Description

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.

CVSS Metrics

  • v3.1LOWScore: 3.5CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
  • v2.0LOWScore: 2.9AV:A/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 5.76% Percentile: 93%

Affected Systems

  • aristac-200_firmware

    < 11.0.0-36

  • aristac-230_firmware

    < 10.0.1-31

  • aristac-235_firmware

    < 10.0.1-31

  • aristac-250_firmware

    < 10.0.1-31

  • aristac-260_firmware

    < 10.0.1-31

  • debianfirmware-nonfree

    all | < 20210818-1 | < 20210818-1 | < 20210818-1

  • debianlinux

    < 5.10.46-1 | < 5.10.46-1 | < 5.10.46-1 | < 5.10.46-1

  • ubuntulinux

    all | < 4.15.0-151.157 | < 5.4.0-77.86

  • ubuntulinux-aws

    all | < 4.15.0-1109.116 | < 5.4.0-1051.53

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1051.53~18.04.1

  • ubuntulinux-aws-5.8

    < 5.8.0-1038.40~20.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2051.53 | all | < 5.4.0-1069.73+fips2

  • ubuntulinux-aws-hwe

    < 4.15.0-1109.116~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1121.134~14.04.1 | < 4.15.0-1121.134~16.04.1 | all | < 5.4.0-1051.53

  • ubuntulinux-azure-4.15

    < 4.15.0-1121.134

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1051.53~18.04.1

  • ubuntulinux-azure-5.8

    < 5.8.0-1036.38~20.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde-5.15

    < 5.15.0-1114.123~20.04.1

  • ubuntulinux-azure-fips

    < 4.15.0-2033.37 | all | < 5.4.0-1073.76+fips1

  • ubuntulinux-bluefield

    all | < 5.4.0-1013.16

  • ubuntulinux-dell300x

    < 4.15.0-1027.32

  • ubuntulinux-fips

    all | < 4.15.0-1066.75 | < 5.4.0-1028.32

  • ubuntulinux-gcp

    < 4.15.0-1106.120~16.04.1 | all | < 5.4.0-1046.49

  • ubuntulinux-gcp-4.15

    < 4.15.0-1106.120

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1046.49~18.04.1

  • ubuntulinux-gcp-5.8

    < 5.8.0-1035.37~20.04.1

  • ubuntulinux-gcp-edge

    all

  • ubuntulinux-gcp-fips

    < 4.15.0-2016.18 | all | < 5.4.0-1067.71~20.04.1

  • ubuntulinux-gke

    < 5.4.0-1046.48

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.4

    < 5.4.0-1046.48~18.04.1

  • ubuntulinux-gkeop

    < 5.4.0-1018.19

  • ubuntulinux-gkeop-5.4

    < 5.4.0-1018.19~18.04.1

  • ubuntulinux-hwe

    < 4.15.0-151.157~16.04.1 | all

  • ubuntulinux-hwe-5.4

    < 5.4.0-77.86~18.04.1

  • ubuntulinux-hwe-5.8

    < 5.8.0-59.66~20.04.1

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    all | < 4.15.0-1097.99 | < 5.4.0-1041.42

  • ubuntulinux-lts-xenial

    all

  • ubuntulinux-oem

    all

  • ubuntulinux-oem-5.10

    < 5.10.0-1032.33

  • ubuntulinux-oem-5.6

    all

  • ubuntulinux-oracle

    < 4.15.0-1078.86~16.04.1 | < 4.15.0-1078.86 | < 5.4.0-1048.52

  • ubuntulinux-oracle-5.0

    all

Showing first 50 affected entries in server-rendered view.

References (20)