Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2020-24587

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.

SeverityLOW
CVSS2.6
CWECWE-327
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco Webex Room Phone cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco TelePresence Endpoint Software (TC/CE) cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco TelePresence cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco IP phone cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco IP Phones with Multiplatform Firmware cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco Business Wireless Access Point Software cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco Aironet Access Point Software (IOS XE Controller) cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco Aironet Access Point Software cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln