CVE-2020-24586 - CVE House
Back to Database
Status published Low CVE-2020-24586

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2,...

Vulnerability Description

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-24586

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ieee 802.11, debian linux, mac80211, c-250 firmware, c-260 firmware, c-230 firmware, c-235 firmware, c-200 firmware, ax210 firmware, ax201 firmware, ax200 firmware, ac 9560 firmware, ac 9462 firmware, ac 9461 firmware, ac 9260 firmware, ac 8265 firmware, ac 8260 firmware, ac 3168 firmware, ac 7265 firmware, ac 3165 firmware, ax1675 firmware, ax1650 firmware, ac 1550 firmware, linux kernel
Vulnerable Versions:
9.0, 0, 4.4, 4.9, 4.14, 4.19, 5.4, 5.10, 5.12

Timeline

Official Publish: May 11th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.