IM
IronMonkey Threat Research

CVE-2020-26142 MEDIUM

Published: 2021-05-11 | Last Modified: 2024-11-21 | Status: Modified

Description

An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configuration.

Additional Descriptions (1)

Se detectó un problema en el kernel en OpenBSD versión 6.6. Las implementaciones WEP, WPA, WPA2 y WPA3 tratan las tramas fragmentadas como tramas completas. Un adversario puede abusar de esto para inyectar paquetes de red arbitrarios, independientemente de la configuración de la red

CVSS Metrics

Base Score: 5.3 (MEDIUM)

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 1.6

Impact Score: 3.6

Base Score: 2.6 (LOW)

AV:N/AC:H/Au:N/C:N/I:P/A:N

Access VectorNETWORK
Access ComplexityHIGH
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 4.9

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-74

Affected Products

Vendor Product Version Update Type
openbsd openbsd 6.6 <built-in method update of dict object at 0x72a9cc60c840> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:openbsd:openbsd:6.6:*:*:*:*:*:*:*
Notification
Message here