CVE-2020-26141
Last modified
CVE-2020-26141 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. EPSS estimates a 3.07% chance of exploitation in the next 30 days.
Description
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TKIP frames. An adversary can abuse this to inject and possibly decrypt packets in WPA or WPA2 networks that support the TKIP data-confidentiality protocol.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alfa | Awus036h Firmware | 6.1316.1209 |
| Cisco | Meraki Gr10 Firmware | < 27.7.1 |
| Cisco | Meraki Gr60 Firmware | < 27.7.1 |
| Cisco | Meraki Mr20 Firmware | < 27.7.1 |
| Cisco | Meraki Mr30h Firmware | < 27.7.1 |
| Cisco | Meraki Mr33 Firmware | < 27.7.1 |
| Cisco | Meraki Mr36 Firmware | < 27.7.1 |
| Cisco | Meraki Mr42 Firmware | < 27.7.1 |
| Cisco | Meraki Mr42e Firmware | < 27.7.1 |
| Cisco | Meraki Mr44 Firmware | < 27.7.1 |
| Cisco | Meraki Mr45 Firmware | < 27.7.1 |
| Cisco | Meraki Mr46 Firmware | < 27.7.1 |
| Cisco | Meraki Mr46e Firmware | < 27.7.1 |
| Cisco | Meraki Mr52 Firmware | < 27.7.1 |
| Cisco | Meraki Mr53 Firmware | < 27.7.1 |
| Cisco | Meraki Mr53e Firmware | < 27.7.1 |
| Cisco | Meraki Mr55 Firmware | < 27.7.1 |
| Cisco | Meraki Mr56 Firmware | < 27.7.1 |
| Cisco | Meraki Mr70 Firmware | < 27.7.1 |
| Cisco | Meraki Mr74 Firmware | < 27.7.1 |
| Cisco | Meraki Mr76 Firmware | < 27.7.1 |
| Cisco | Meraki Mr84 Firmware | < 27.7.1 |
| Cisco | Meraki Mr86 Firmware | < 27.7.1 |
| Cisco | Meraki Mr12 Firmware | < 26.8.3 |
| Cisco | Meraki Mr18 Firmware | < 26.8.3 |
| Cisco | Meraki Mr26 Firmware | < 26.8.3 |
| Cisco | Meraki Mr32 Firmware | < 26.8.3 |
| Cisco | Meraki Mr34 Firmware | < 26.8.3 |
| Cisco | Meraki Mr62 Firmware | < 26.8.3 |
| Cisco | Meraki Mr66 Firmware | < 26.8.3 |
| Cisco | Meraki Mr72 Firmware | < 26.8.3 |
| Cisco | Meraki Mx64w Firmware | < 17.0 |
| Cisco | Meraki Mx65w Firmware | < 17.0 |
| Cisco | Meraki Mx67w Firmware | < 17.0 |
| Cisco | Meraki Mx67cw Firmware | < 17.0 |
| Cisco | Meraki Mx68w Firmware | < 17.0 |
| Cisco | Meraki Mx68cw Firmware | < 17.0 |
| Cisco | Meraki Z3 Firmware | < 17.0 |
| Cisco | Meraki Z3c Firmware | < 17.0 |
| Cisco | Wireless Ip Phone 8821 Firmware | < 11.0\(6\)sr2 |
| Cisco | Ip Phone 6861 Firmware | < 11.3\(5\) |
| Cisco | Ip Phone 8861 Firmware | < 11.3\(5\) |
| Cisco | Ip Phone 8861 Firmware | < 14.1\(1\) |
| Cisco | Ip Phone 8865 Firmware | < 14.1\(1\) |
| Cisco | Ip Conference Phone 8832 Firmware | < 14.1\(1\) |
| Cisco | Webex Room Series Firmware | < 1.2\(0\)sr1 |
| Cisco | Webex Desk Series Firmware | < 1.2\(0\)sr1 |
| Cisco | Webex Board Series Firmware | < 10.8.2.5 |
| Cisco | Webex Wireless Phone 860 Firmware | < 1.4\(0\) |
| Cisco | Webex Wireless Phone 840 Firmware | < 1.4\(0\) |
Showing 50 of 96 affected configurations. See NVD for the full list.
References
- http://www.openwall.com/lists/oss-security/2021/05/11/12Mailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdfThird Party Advisory
- https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.mdThird Party Advisory
- https://www.fragattacks.comThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/05/11/12Mailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdfThird Party Advisory
- https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.mdThird Party Advisory
- https://www.fragattacks.comThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-26141?
How severe is CVE-2020-26141?
How do I fix CVE-2020-26141?
Are you affected by CVE-2020-26141?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
