CVE-2020-26140
⚪ Do wiadomości
Luka w sterowniku ALFA dla AWUS036H pozwala na wstrzykiwanie danych w chronionej sieci Wi-Fi.
CVSS
6.5
EPSS
2.9%
Exploit
none
Vendor
cisco
Opis źródłowy (NVD)
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 2.9% |
| Opublikowano (NVD) | 2021-05-11 20:15:08 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:16:58 UTC |
Referencje
- http://www.openwall.com/lists/oss-security/2021/05/11/12 ([email protected]) [Mailing List, Third Party Advisory]
- https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdf ([email protected]) [Third Party Advisory]
- https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md ([email protected]) [Third Party Advisory]
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu ([email protected]) [Third Party Advisory]
- https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63 ([email protected]) [Third Party Advisory]
- https://www.fragattacks.com ([email protected]) [Third Party Advisory]
- https://cert-portal.siemens.com/productcert/html/ssa-019200.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)
- https://cert-portal.siemens.com/productcert/html/ssa-913875.html (0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)