Skip to main content

CVE detail

CVE-2020-24587

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.

CVSS 2.6 · LowBuzz score 27.4

Buzz score

Why this CVE is surfacing

Buzz score total 27.4

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 17.9 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
17.9
5 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
5 source links · newest first
  • Impacted vendors have released security advisories in response to the recently disclosed Wi-Fi vulnerabilities collectively tracked as FragAttacks . A dozen CVE identifiers have been assigned to the FragAttacks (fragmentation and aggregation attacks) flaws discovered last year by researcher Mathy Vanhoef, including three for design flaws and nine for implementation flaws. Vanhoef tested 75 Wi-Fi devices and found that they were all affected by at least one vulnerability, but most of them were impacted by multiple issues. This suggests that a vast majority — if not all — devices with Wi-Fi capabilities are exposed to attacks. The design flaws are more difficult to exploit, while the implementation weaknesses are easier to use in attacks. The researcher demonstrated that the vulnerabilities can allow an attacker who is within Wi-Fi range of the targeted device to conduct various activities, including redirect users to arbitrary websites, take control of devices on the network, bypass ro…

    newswww.securityweek.comMay 14, 2021, 3:08 PM
  • Microsoft Patch Tuesday for May 2021 security updates addressed 55 vulnerabilities, four are rated as Critical. Microsoft Patch Tuesday for May 2021 security updates address 55 vulnerabilities in Microsoft Windows, .NET Core and Visual Studio, Internet Explorer (IE), Microsoft Office, SharePoint Server, Open-Source Software, Hyper-V, Skype for Business and Microsoft Lync, and Exchange Server. Four […]

    newssecurityaffairs.comMay 12, 2021, 9:39 PM
  • Security researcher discovered a series of flaws, collectively tracked as FragAttacks, that impact the WiFi devices sold for the past 24 years. Belgian security researcher Mathy Vanhoef disclosed the details of a multiple vulnerabilities, tracked as FragAttacks, that affect WiFi devices exposed them to remote attacks. Some the flaws discovered by the experts date back as […]

    newssecurityaffairs.comMay 12, 2021, 4:32 PM
  • On this May 2021 Patch Tuesday: Adobe has fixed a Reader flaw exploited in attacks in the wild, as well as delivered security updates for eleven other products, including Magento, Adobe InDesign, Adobe After Effects, Adobe Creative Cloud Desktop Application, and others Microsoft has plugged 55 security holes, none actively exploited SAP has released 14 new and updated security patches Adobe updates Adobe has released security updates for 12 of its products, fixing a total of … More →

    newswww.helpnetsecurity.comMay 12, 2021, 8:40 AM
  • A new set of vulnerabilities with an aggressive name and their own website almost always bodes ill. The name FragAttack is…

    newswww.malwarebytes.comMay 11, 2021, 5:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence