CVE-2020-24587

Advisory lineage Upstream: 0 Downstream: 35
Modified
Published: 11 May 2021, 00:00
Last modified:04 Aug 2024, 15:19

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
2.6 LOW
v3.1 (nvd)
EPSS Score
0.55% LOW
1% probability +0.13%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

11 May 2021, 00:00
Published
Vulnerability first disclosed
04 Aug 2024, 15:19
Last Modified
Vulnerability information updated

Description

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.

CVSS Metrics

  • v3.1LOWScore: 2.6CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
  • v2.0LOWScore: 1.8AV:A/AC:H/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.55% Percentile: 68%

Techniques & Countermeasures

  • CWE-327Use of a Broken or Risky Cryptographic Algorithm

    The product uses a broken or risky cryptographic algorithm or protocol.

Affected Systems

  • aristac-100_firmware

    na

  • aristac-110_firmware

    na

  • aristac-120_firmware

    na

  • aristac-130_firmware

    na

  • aristac-200_firmware

    na

  • aristac-230_firmware

    na

  • aristac-235_firmware

    na

  • aristac-250_firmware

    na

  • aristac-260_firmware

    na

  • aristac-65_firmware

    na

  • aristac-75_firmware

    na

  • aristao-105_firmware

    na

  • aristao-90_firmware

    na

  • aristaw-118_firmware

    na

  • aristaw-68_firmware

    na

  • cisco1100_firmware

    na

  • cisco1100-4p_firmware

    na

  • cisco1100-8p_firmware

    na

  • cisco1101-4p_firmware

    na

  • cisco1109-2p_firmware

    na

  • cisco1109-4p_firmware

    na

  • ciscoaironet_1532_firmware

    na

  • ciscoaironet_1542d_firmware

    na

  • ciscoaironet_1542i_firmware

    na

  • ciscoaironet_1552_firmware

    na

  • ciscoaironet_1552h_firmware

    na

  • ciscoaironet_1572_firmware

    na

  • ciscoaironet_1702_firmware

    na

  • ciscoaironet_1800_firmware

    na

  • ciscoaironet_1800i_firmware

    na

  • ciscoaironet_1810_firmware

    na

  • ciscoaironet_1810w_firmware

    na

  • ciscoaironet_1815_firmware

    na

  • ciscoaironet_1815i_firmware

    na

  • ciscoaironet_1832_firmware

    na

  • ciscoaironet_1842_firmware

    na

  • ciscoaironet_1852_firmware

    na

  • ciscoaironet_2702_firmware

    na

  • ciscoaironet_2800_firmware

    na

  • ciscoaironet_2800e_firmware

    na

  • ciscoaironet_2800i_firmware

    na

  • ciscoaironet_3702_firmware

    na

  • ciscoaironet_3800_firmware

    na

  • ciscoaironet_3800e_firmware

    na

  • ciscoaironet_3800i_firmware

    na

  • ciscoaironet_3800p_firmware

    na

  • ciscoaironet_4800_firmware

    na

  • ciscoaironet_ap803_firmware

    na

  • ciscoaironet_iw3702_firmware

    na

  • ciscocatalyst_9105_firmware

    na

Showing first 50 affected entries in server-rendered view.

References (9)