Fragmentation Security Weakness in Wi-Fi Standards Affecting Multiple Vendors
CVE-2020-24586
3.5LOW
What is CVE-2020-24586?
The Wi-Fi security standards, including WPA, WPA2, and WPA3, are affected by a vulnerability that arises from the handling of fragmented frames. In certain situations, upon connecting or reconnecting to a network, received fragments may remain in memory unaltered. This oversight can allow an attacker to exploit fragmented frames encrypted with WEP, CCMP, or GCMP, thereby injecting arbitrary network packets or potentially exfiltrating sensitive user data. The vulnerability underscores the importance of secure memory management practices in network environments.