CVE-2020-26139
MEDIUM EPSS 92.9%
Published May 11, 20215y ago · Modified Jun 17, 20262w ago
5.3 CVSS 3.1
Published May 11, 2021 5y ago
Last Modified Jun 17, 2026 2w ago
Description
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector Adjacent
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
92.9% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-287 Improper Authentication Authentication
Affected Products 330
| Vendor | Product | Version | Range |
|---|---|---|---|
| netbsd | netbsd | 7.1 | any |
| debian | debian_linux | 9.0 | any |
| arista | c-100_firmware | * | any |
| arista | c-100 | * | any |
| arista | c-110_firmware | * | any |
| arista | c-110 | * | any |
| arista | c-120_firmware | * | any |
| arista | c-120 | * | any |
| arista | c-130_firmware | * | any |
| arista | c-130 | * | any |
| arista | c-200_firmware | * | any |
| arista | c-200 | * | any |
| arista | c-230_firmware | * | any |
| arista | c-230 | * | any |
| arista | c-235_firmware | * | any |
| arista | c-235 | * | any |
| arista | c-250_firmware | * | any |
| arista | c-250 | * | any |
| arista | c-260_firmware | * | any |
| arista | c-260 | * | any |
| arista | c-65_firmware | * | any |
| arista | c-65 | * | any |
| arista | c-75_firmware | * | any |
| arista | c-75 | * | any |
| arista | o-105_firmware | * | any |
| arista | o-105 | * | any |
| arista | o-90_firmware | * | any |
| arista | o-90 | * | any |
| arista | w-118_firmware | * | any |
| arista | w-118 | * | any |
| arista | w-68_firmware | * | any |
| arista | w-68 | * | any |
| cisco | 1100_firmware | * | any |
| cisco | 1100 | * | any |
| cisco | 1100-4p_firmware | * | any |
| cisco | 1100-4p | * | any |
| cisco | 1100-8p_firmware | * | any |
| cisco | 1100-8p | * | any |
| cisco | 1101-4p_firmware | * | any |
| cisco | 1101-4p | * | any |
| cisco | 1109-2p_firmware | * | any |
| cisco | 1109-2p | * | any |
| cisco | 1109-4p_firmware | * | any |
| cisco | 1109-4p | * | any |
| cisco | aironet_1532_firmware | * | any |
| cisco | aironet_1532 | * | any |
| cisco | aironet_1542d_firmware | * | any |
| cisco | aironet_1542d | * | any |
| cisco | aironet_1542i_firmware | * | any |
| cisco | aironet_1542i | * | any |
| cisco | aironet_1552_firmware | * | any |
| cisco | aironet_1552 | * | any |
| cisco | aironet_1552h_firmware | * | any |
| cisco | aironet_1552h | * | any |
| cisco | aironet_1572_firmware | * | any |
| cisco | aironet_1572 | * | any |
| cisco | aironet_1702_firmware | * | any |
| cisco | aironet_1702 | * | any |
| cisco | aironet_1800_firmware | * | any |
| cisco | aironet_1800 | * | any |
| cisco | aironet_1800i_firmware | * | any |
| cisco | aironet_1800i | * | any |
| cisco | aironet_1810_firmware | * | any |
| cisco | aironet_1810 | * | any |
| cisco | aironet_1810w_firmware | * | any |
| cisco | aironet_1810w | * | any |
| cisco | aironet_1815_firmware | * | any |
| cisco | aironet_1815 | * | any |
| cisco | aironet_1815i_firmware | * | any |
| cisco | aironet_1815i | * | any |
| cisco | aironet_1832_firmware | * | any |
| cisco | aironet_1832 | * | any |
| cisco | aironet_1842_firmware | * | any |
| cisco | aironet_1842 | * | any |
| cisco | aironet_1852_firmware | * | any |
| cisco | aironet_1852 | * | any |
| cisco | aironet_2702_firmware | * | any |
| cisco | aironet_2702 | * | any |
| cisco | aironet_2800_firmware | * | any |
| cisco | aironet_2800 | * | any |
| cisco | aironet_2800e_firmware | * | any |
| cisco | aironet_2800e | * | any |
| cisco | aironet_2800i_firmware | * | any |
| cisco | aironet_2800i | * | any |
| cisco | aironet_3702_firmware | * | any |
| cisco | aironet_3702 | * | any |
| cisco | aironet_3800_firmware | * | any |
| cisco | aironet_3800 | * | any |
| cisco | aironet_3800e_firmware | * | any |
| cisco | aironet_3800e | * | any |
| cisco | aironet_3800i_firmware | * | any |
| cisco | aironet_3800i | * | any |
| cisco | aironet_3800p_firmware | * | any |
| cisco | aironet_3800p | * | any |
| cisco | aironet_4800_firmware | * | any |
| cisco | aironet_4800 | * | any |
| cisco | aironet_ap803_firmware | * | any |
| cisco | aironet_ap803 | * | any |
| cisco | aironet_iw3702_firmware | * | any |
| cisco | aironet_iw3702 | * | any |
| cisco | catalyst_9105_firmware | * | any |
| cisco | catalyst_9105 | * | any |
| cisco | catalyst_9105axi_firmware | * | any |
| cisco | catalyst_9105axi | * | any |
| cisco | catalyst_9105axw_firmware | * | any |
| cisco | catalyst_9105axw | * | any |
| cisco | catalyst_9115_firmware | * | any |
| cisco | catalyst_9115 | * | any |
| cisco | catalyst_9115_ap_firmware | * | any |
| cisco | catalyst_9115_ap | * | any |
| cisco | catalyst_9115axe_firmware | * | any |
| cisco | catalyst_9115axe | * | any |
| cisco | catalyst_9115axi_firmware | * | any |
| cisco | catalyst_9115axi | * | any |
| cisco | catalyst_9117_firmware | * | any |
| cisco | catalyst_9117 | * | any |
| cisco | catalyst_9117_ap_firmware | * | any |
| cisco | catalyst_9117_ap | * | any |
| cisco | catalyst_9117axi_firmware | * | any |
| cisco | catalyst_9117axi | * | any |
| cisco | catalyst_9120_firmware | * | any |
| cisco | catalyst_9120 | * | any |
| cisco | catalyst_9120_ap_firmware | * | any |
| cisco | catalyst_9120_ap | * | any |
| cisco | catalyst_9120axe_firmware | * | any |
| cisco | catalyst_9120axe | * | any |
| cisco | catalyst_9120axi_firmware | * | any |
| cisco | catalyst_9120axi | * | any |
| cisco | catalyst_9120axp_firmware | * | any |
| cisco | catalyst_9120axp | * | any |
| cisco | catalyst_9124_firmware | * | any |
| cisco | catalyst_9124 | * | any |
| cisco | catalyst_9124axd_firmware | * | any |
| cisco | catalyst_9124axd | * | any |
| cisco | catalyst_9124axi_firmware | * | any |
| cisco | catalyst_9124axi | * | any |
| cisco | catalyst_9130_firmware | * | any |
| cisco | catalyst_9130 | * | any |
| cisco | catalyst_9130_ap_firmware | * | any |
| cisco | catalyst_9130_ap | * | any |
| cisco | catalyst_9130axe_firmware | * | any |
| cisco | catalyst_9130axe | * | any |
| cisco | catalyst_9130axi_firmware | * | any |
| cisco | catalyst_9130axi | * | any |
| cisco | catalyst_iw6300_firmware | * | any |
| cisco | catalyst_iw6300 | * | any |
| cisco | catalyst_iw6300_ac_firmware | * | any |
| cisco | catalyst_iw6300_ac | * | any |
| cisco | catalyst_iw6300_dc_firmware | * | any |
| cisco | catalyst_iw6300_dc | * | any |
| cisco | catalyst_iw6300_dcw_firmware | * | any |
| cisco | catalyst_iw6300_dcw | * | any |
| cisco | esw6300_firmware | * | any |
| cisco | esw6300 | * | any |
| cisco | ip_phone_6861_firmware | * | any |
| cisco | ip_phone_6861 | * | any |
| cisco | ip_phone_8821_firmware | * | any |
| cisco | ip_phone_8821 | * | any |
| cisco | ip_phone_8832_firmware | * | any |
| cisco | ip_phone_8832 | * | any |
| cisco | ip_phone_8861_firmware | * | any |
| cisco | ip_phone_8861 | * | any |
| cisco | ip_phone_8865_firmware | * | any |
| cisco | ip_phone_8865 | * | any |
| cisco | ir829-2lte-ea-ak9_firmware | * | any |
| cisco | ir829-2lte-ea-ak9 | * | any |
| cisco | ir829-2lte-ea-bk9_firmware | * | any |
| cisco | ir829-2lte-ea-bk9 | * | any |
| cisco | ir829-2lte-ea-ek9_firmware | * | any |
| cisco | ir829-2lte-ea-ek9 | * | any |
| cisco | ir829gw-lte-ga-ck9_firmware | * | any |
| cisco | ir829gw-lte-ga-ck9 | * | any |
| cisco | ir829gw-lte-ga-ek9_firmware | * | any |
| cisco | ir829gw-lte-ga-ek9 | * | any |
| cisco | ir829gw-lte-ga-sk9_firmware | * | any |
| cisco | ir829gw-lte-ga-sk9 | * | any |
| cisco | ir829gw-lte-ga-zk9_firmware | * | any |
| cisco | ir829gw-lte-ga-zk9 | * | any |
| cisco | ir829gw-lte-na-ak9_firmware | * | any |
| cisco | ir829gw-lte-na-ak9 | * | any |
| cisco | ir829gw-lte-vz-ak9_firmware | * | any |
| cisco | ir829gw-lte-vz-ak9 | * | any |
| cisco | meraki_gr10_firmware | * | any |
| cisco | meraki_gr10 | * | any |
| cisco | meraki_gr60_firmware | * | any |
| cisco | meraki_gr60 | * | any |
| cisco | meraki_mr12_firmware | * | any |
| cisco | meraki_mr12 | * | any |
| cisco | meraki_mr20_firmware | * | any |
| cisco | meraki_mr20 | * | any |
| cisco | meraki_mr26_firmware | * | any |
| cisco | meraki_mr26 | * | any |
| cisco | meraki_mr30h_firmware | * | any |
| cisco | meraki_mr30h | * | any |
| cisco | meraki_mr32_firmware | * | any |
| cisco | meraki_mr32 | * | any |
| cisco | meraki_mr33_firmware | * | any |
| cisco | meraki_mr33 | * | any |
| cisco | meraki_mr34_firmware | * | any |
| cisco | meraki_mr34 | * | any |
| cisco | meraki_mr36_firmware | * | any |
| cisco | meraki_mr36 | * | any |
| cisco | meraki_mr42_firmware | * | any |
| cisco | meraki_mr42 | * | any |
| cisco | meraki_mr42e_firmware | * | any |
| cisco | meraki_mr42e | * | any |
| cisco | meraki_mr44_firmware | * | any |
| cisco | meraki_mr44 | * | any |
| cisco | meraki_mr45_firmware | * | any |
| cisco | meraki_mr45 | * | any |
| cisco | meraki_mr46_firmware | * | any |
| cisco | meraki_mr46 | * | any |
| cisco | meraki_mr46e_firmware | * | any |
| cisco | meraki_mr46e | * | any |
| cisco | meraki_mr52_firmware | * | any |
| cisco | meraki_mr52 | * | any |
| cisco | meraki_mr53_firmware | * | any |
| cisco | meraki_mr53 | * | any |
| cisco | meraki_mr53e_firmware | * | any |
| cisco | meraki_mr53e | * | any |
| cisco | meraki_mr55_firmware | * | any |
| cisco | meraki_mr55 | * | any |
| cisco | meraki_mr56_firmware | * | any |
| cisco | meraki_mr56 | * | any |
| cisco | meraki_mr62_firmware | * | any |
| cisco | meraki_mr62 | * | any |
| cisco | meraki_mr66_firmware | * | any |
| cisco | meraki_mr66 | * | any |
| cisco | meraki_mr70_firmware | * | any |
| cisco | meraki_mr70 | * | any |
| cisco | meraki_mr72_firmware | * | any |
| cisco | meraki_mr72 | * | any |
| cisco | meraki_mr74_firmware | * | any |
| cisco | meraki_mr74 | * | any |
| cisco | meraki_mr76_firmware | * | any |
| cisco | meraki_mr76 | * | any |
| cisco | meraki_mr84_firmware | * | any |
| cisco | meraki_mr84 | * | any |
| cisco | meraki_mr86_firmware | * | any |
| cisco | meraki_mr86 | * | any |
| cisco | meraki_mx64w_firmware | * | any |
| cisco | meraki_mx64w | * | any |
| cisco | meraki_mx65w_firmware | * | any |
| cisco | meraki_mx65w | * | any |
| cisco | meraki_mx67cw_firmware | * | any |
| cisco | meraki_mx67cw | * | any |
| cisco | meraki_mx67w_firmware | * | any |
| cisco | meraki_mx67w | * | any |
| cisco | meraki_mx68cw_firmware | * | any |
| cisco | meraki_mx68cw | * | any |
| cisco | meraki_mx68w_firmware | * | any |
| cisco | meraki_mx68w | * | any |
| cisco | meraki_z3_firmware | * | any |
| cisco | meraki_z3 | * | any |
| cisco | meraki_z3c_firmware | * | any |
| cisco | meraki_z3c | * | any |
| cisco | webex_board_55_firmware | * | any |
| cisco | webex_board_55 | * | any |
| cisco | webex_board_55s_firmware | * | any |
| cisco | webex_board_55s | * | any |
| cisco | webex_board_70_firmware | * | any |
| cisco | webex_board_70 | * | any |
| cisco | webex_board_70s_firmware | * | any |
| cisco | webex_board_70s | * | any |
| cisco | webex_board_85s_firmware | * | any |
| cisco | webex_board_85s | * | any |
| cisco | webex_dx70_firmware | * | any |
| cisco | webex_dx70 | * | any |
| cisco | webex_dx80_firmware | * | any |
| cisco | webex_dx80 | * | any |
| cisco | webex_room_55_firmware | * | any |
| cisco | webex_room_55 | * | any |
| cisco | webex_room_55_dual_firmware | * | any |
| cisco | webex_room_55_dual | * | any |
| cisco | webex_room_70_firmware | * | any |
| cisco | webex_room_70 | * | any |
| cisco | webex_room_70_dual_firmware | * | any |
| cisco | webex_room_70_dual | * | any |
| cisco | webex_room_70_dual_g2_firmware | * | any |
| cisco | webex_room_70_dual_g2 | * | any |
| cisco | webex_room_70_single_firmware | * | any |
| cisco | webex_room_70_single | * | any |
| cisco | webex_room_70_single_g2_firmware | * | any |
| cisco | webex_room_70_single_g2 | * | any |
| cisco | webex_room_kit_firmware | * | any |
| cisco | webex_room_kit | * | any |
| cisco | webex_room_kit_mini_firmware | * | any |
| cisco | webex_room_kit_mini | * | any |
| intel | ac_8260_firmware | * | any |
| intel | ac_8260 | * | any |
| intel | ac_8265_firmware | * | any |
| intel | ac_8265 | * | any |
| intel | ac_9260_firmware | * | any |
| intel | ac_9260 | * | any |
| intel | ac_9560_firmware | * | any |
| intel | ac_9560 | * | any |
| intel | killer_ac_1550_firmware | * | any |
| intel | killer_ac_1550 | * | any |
| intel | killer_wi-fi_6_ax1650_firmware | * | any |
| intel | killer_wi-fi_6_ax1650 | * | any |
| intel | killer_wi-fi_6e_ax1675_firmware | * | any |
| intel | killer_wi-fi_6e_ax1675 | * | any |
| intel | proset_ac_3165_firmware | * | any |
| intel | proset_ac_3165 | * | any |
| intel | proset_ac_3168_firmware | * | any |
| intel | proset_ac_3168 | * | any |
| intel | proset_ac_8260_firmware | * | any |
| intel | proset_ac_8260 | * | any |
| intel | proset_ac_8265_firmware | * | any |
| intel | proset_ac_8265 | * | any |
| intel | proset_ac_9260_firmware | * | any |
| intel | proset_ac_9260 | * | any |
| intel | proset_ac_9461_firmware | * | any |
| intel | proset_ac_9461 | * | any |
| intel | proset_ac_9462_firmware | * | any |
| intel | proset_ac_9462 | * | any |
| intel | proset_ac_9560_firmware | * | any |
| intel | proset_ac_9560 | * | any |
| intel | proset_wi-fi_6_ax200_firmware | * | any |
| intel | proset_wi-fi_6_ax200 | * | any |
| intel | proset_wi-fi_6_ax201_firmware | * | any |
| intel | proset_wi-fi_6_ax201 | * | any |
| intel | proset_wi-fi_6e_ax210_firmware | * | any |
| intel | proset_wi-fi_6e_ax210 | * | any |
| intel | proset_wireless_7265_\(rev_d\)_firmware | * | any |
| intel | proset_wireless_7265_\(rev_d\) | * | any |
| intel | wi-fi_6_ax200_firmware | * | any |
| intel | wi-fi_6_ax200 | * | any |
| intel | wi-fi_6_ax201_firmware | * | any |
| intel | wi-fi_6_ax201 | * | any |
References 10
- openwall.com http://www.openwall.com/lists/oss-security/2021/05/11/12
- cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-019200.html
- cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-913875.html
- cert-portal.siemens.com https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdf
- github.com https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md
- lists.debian.org https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html
- tools.cisco.com https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu
- arista.com https://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63
- fragattacks.com https://www.fragattacks.com
Remediation
- cert-portal.siemens.com https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdf