IM
IronMonkey Threat Research

CVE-2020-26143 MEDIUM

Published: 2021-05-11 | Last Modified: 2026-04-14 | Status: Modified

Description

An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.

Additional Descriptions (1)

Se detectó un problema en el controlador ALFA Windows 10 versión 1030.36.604 para AWUS036ACH. Las implementaciones WEP, WPA, WPA2 y WPA3 aceptan tramas de texto plano fragmentados en una red Wi-Fi protegida. Un adversario puede abusar de esto para inyectar tramas de datos arbitrarias independientes de la configuración de la red

CVSS Metrics

Base Score: 6.5 (MEDIUM)

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack VectorADJACENT_NETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 3.6

Base Score: 3.3 (LOW)

AV:A/AC:L/Au:N/C:N/I:P/A:N

Access VectorADJACENT_NETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 6.5

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-20

Affected Products

Vendor Product Version Update Type
alfa awus036h_firmware 1030.36.604 <built-in method update of dict object at 0x72a9b0db7980> Operating System
arista c-75_firmware - <built-in method update of dict object at 0x72a9b0c989c0> Operating System
arista o-90_firmware - <built-in method update of dict object at 0x72a9cd079c40> Operating System
arista c-65_firmware - <built-in method update of dict object at 0x72a9cd0c1940> Operating System
arista w-68_firmware - <built-in method update of dict object at 0x72a9cd0c1380> Operating System
siemens scalance_w700_ieee_802.11n_firmware * <built-in method update of dict object at 0x72a9cd0c2cc0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:alfa:awus036h_firmware:1030.36.604:*:*:*:*:windows_10:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:alfa:awus036h:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:arista:c-75_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:arista:c-75:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:arista:o-90_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:arista:o-90:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:arista:c-65_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:arista:c-65:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:arista:w-68_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:arista:w-68:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:scalance_w700_ieee_802.11n_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:scalance_w700_ieee_802.11n:-:*:*:*:*:*:*:*

References

Notification
Message here