ZeroHour

CVE-2020-26139

CVSS 3.1
5.3 medium
EPSS
6%p93
Published
()
Modified
Description

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.

Vendors
netbsddebianaristaciscointel
Products
netbsd, debian linux, c-100 firmware, c-110 firmware, c-120 firmware, c-130 firmware, c-200 firmware, c-230 firmware, c-235 firmware, c-250 firmware, c-260 firmware, c-65 firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news