CVE-2020-26139

MEDIUMCVSS 5.3/10EPSS 6.49%

Last modified

CVE-2020-26139 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. EPSS estimates a 6.49% chance of exploitation in the next 30 days.

Description

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
6.49%

92.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NetbsdNetbsd7.1
DebianDebian Linux9.0
AristaC-100 FirmwareAll versions
AristaC-110 FirmwareAll versions
AristaC-120 FirmwareAll versions
AristaC-130 FirmwareAll versions
AristaC-200 FirmwareAll versions
AristaC-230 FirmwareAll versions
AristaC-235 FirmwareAll versions
AristaC-250 FirmwareAll versions
AristaC-260 FirmwareAll versions
AristaC-65 FirmwareAll versions
AristaC-75 FirmwareAll versions
AristaO-105 FirmwareAll versions
AristaO-90 FirmwareAll versions
AristaW-118 FirmwareAll versions
AristaW-68 FirmwareAll versions
Cisco1100 FirmwareAll versions
Cisco1100-4p FirmwareAll versions
Cisco1100-8p FirmwareAll versions
Cisco1101-4p FirmwareAll versions
Cisco1109-2p FirmwareAll versions
Cisco1109-4p FirmwareAll versions
CiscoAironet 1532 FirmwareAll versions
CiscoAironet 1542d FirmwareAll versions
CiscoAironet 1542i FirmwareAll versions
CiscoAironet 1552 FirmwareAll versions
CiscoAironet 1552h FirmwareAll versions
CiscoAironet 1572 FirmwareAll versions
CiscoAironet 1702 FirmwareAll versions
CiscoAironet 1800 FirmwareAll versions
CiscoAironet 1800i FirmwareAll versions
CiscoAironet 1810 FirmwareAll versions
CiscoAironet 1810w FirmwareAll versions
CiscoAironet 1815 FirmwareAll versions
CiscoAironet 1815i FirmwareAll versions
CiscoAironet 1832 FirmwareAll versions
CiscoAironet 1842 FirmwareAll versions
CiscoAironet 1852 FirmwareAll versions
CiscoAironet 2702 FirmwareAll versions
CiscoAironet 2800 FirmwareAll versions
CiscoAironet 2800e FirmwareAll versions
CiscoAironet 2800i FirmwareAll versions
CiscoAironet 3702 FirmwareAll versions
CiscoAironet 3800 FirmwareAll versions
CiscoAironet 3800e FirmwareAll versions
CiscoAironet 3800i FirmwareAll versions
CiscoAironet 3800p FirmwareAll versions
CiscoAironet 4800 FirmwareAll versions
CiscoAironet Ap803 FirmwareAll versions

Showing 50 of 166 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-26139?
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.
How severe is CVE-2020-26139?
CVE-2020-26139 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 6.49% probability of exploitation in the next 30 days.
How do I fix CVE-2020-26139?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-26139?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST