CVE-2020-24587

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
11/05/2021
Last modified:
01/04/2023

Description

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ieee:ieee_802.11:*:*:*:*:*:*:*:*
cpe:2.3:a:linux:mac80211:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:arista:c-100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:c-100:-:*:*:*:*:*:*:*
cpe:2.3:o:arista:c-110_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:c-110:-:*:*:*:*:*:*:*
cpe:2.3:o:arista:c-120_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:c-120:-:*:*:*:*:*:*:*
cpe:2.3:o:arista:c-130_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:c-130:-:*:*:*:*:*:*:*
cpe:2.3:o:arista:c-200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:c-200:-:*:*:*:*:*:*:*
cpe:2.3:o:arista:c-230_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:arista:c-230:-:*:*:*:*:*:*:*