CVE-2020-26142

An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configuration.
Configurations

Configuration 1 (hide)

cpe:2.3:o:openbsd:openbsd:6.6:*:*:*:*:*:*:*

History

03 Dec 2021, 21:12

Type Values Removed Values Added
References (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu - (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu - Third Party Advisory
References (MISC) https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63 - (MISC) https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63 - Third Party Advisory

28 Oct 2021, 15:15

Type Values Removed Values Added
References
  • (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu -
  • (MISC) https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63 -

22 Sep 2021, 18:20

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : 7.5
v2 : 2.6
v3 : 5.3

20 May 2021, 17:30

Type Values Removed Values Added
CWE CWE-74
CPE cpe:2.3:o:openbsd:openbsd:6.6:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (MLIST) http://www.openwall.com/lists/oss-security/2021/05/11/12 - (MLIST) http://www.openwall.com/lists/oss-security/2021/05/11/12 - Mailing List, Third Party Advisory
References (MISC) https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md - (MISC) https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md - Third Party Advisory
References (MISC) https://www.fragattacks.com - (MISC) https://www.fragattacks.com - Third Party Advisory

11 May 2021, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-11 20:15

Updated : 2023-12-10 13:55


NVD link : CVE-2020-26142

Mitre link : CVE-2020-26142

CVE.ORG link : CVE-2020-26142


JSON object : View

Products Affected

openbsd

  • openbsd
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')