PT-2021-5619 · Google+2 · Google Chrome+2

Hugo Hue

+1

·

Published

2021-09-24

·

Updated

2024-06-15

·

CVE-2021-37964

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome on ChromeOS versions prior to 94.0.4606.54
Description The issue is related to inappropriate implementation in ChromeOS Networking, allowing a remote attacker with a rogue wireless access point to potentially carry out a wifi impersonation attack via a crafted ONC file. This could enable the attacker to gain privileged access to the infrastructure.
Recommendations For Google Chrome on ChromeOS versions prior to 94.0.4606.54, update to version 94.0.4606.54 or later to resolve the issue. As a temporary workaround, consider restricting access to wireless networks until the update is applied. Avoid using crafted ONC files in the affected API endpoint until the issue is resolved.

Fix

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2909
ALT-PU-2021-2987
ALT-PU-2021-2988
ALT-PU-2021-3044
ALT-PU-2021-3050
ALT-PU-2021-3436
ALT-PU-2021-3603
BDU:2022-00054
CVE-2021-37964
DSA-5046-1
OPENSUSE-SU-2021:1339-1
OPENSUSE-SU-2021:1350-1
OPENSUSE-SU-2021_1350-1
OPENSUSE-SU-2024:11555-1
OPENSUSE-SU-2024:12948-1

Affected Products

Alt Linux
Google Chrome
Suse