SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-26139

This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.

MEDIUM 5.3EPSS 6.49%

Does this matter?

Lower severity and a low EPSS score (6.49%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
6.49% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
netbsd/netbsd · debian/debian linux · arista/c-100 firmware · arista/c-110 firmware · arista/c-120 firmware · arista/c-130 firmware · arista/c-200 firmware · arista/c-230 firmware · arista/c-235 firmware · arista/c-250 firmware · arista/c-260 firmware · arista/c-65 firmware · arista/c-75 firmware · arista/o-105 firmware · arista/o-90 firmware · arista/w-118 firmware · arista/w-68 firmware · cisco/1100 firmware · cisco/1100-4p firmware · cisco/1100-8p firmware · +40 more
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.