PT-2021-3060 · Openbsd · Openbsd

Mathy Vanhoef

·

Published

2021-05-11

·

Updated

2022-04-29

·

CVE-2020-26142

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenBSD version 6.6
Description An issue was discovered in the kernel where the WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. This allows an adversary to inject arbitrary network packets, independent of the network configuration. The vulnerability exists due to the lack of measures to neutralize special elements in the implementation of these algorithms.
Recommendations For OpenBSD version 6.6, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02667
CVE-2020-26142
OESA-2022-1621

Affected Products

Openbsd