CVE-2020-24587

Published May 11, 2021

Last updated 2 years ago

Overview

Description
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.
Source
cve@mitre.org
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
2.6
Impact score
1.4
Exploitability score
1.2
Vector string
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Severity
LOW

CVSS 2.0

Type
Primary
Base score
1.8
Impact score
2.9
Exploitability score
3.2
Vector string
AV:A/AC:H/Au:N/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-327

Social media

Hype score
Not currently trending

Configurations