PT-2021-3311 · Unknown+12 · 802.11 Standard+12
Published
2016-03-17
·
Updated
2026-03-10
·
CVE-2020-24587
CVSS v3.1
2.6
Low
| Vector | AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
802.11 standard (affected versions not specified)
Description
The issue concerns the 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP). It does not require that all fragments of a frame are encrypted under the same key, allowing an adversary to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed. This can enable an attacker to forge encrypted frames and potentially exfiltrate sensitive data from a targeted device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of a Broken Cryptographic Algorithm
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
802.11 Standard
Alt Linux
Almalinux
Astra Linux
Centos
Check Point Gaia
Debian
Fortios
Linuxmint
Red Hat
Suse
Ubuntu
Windows