The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "20h2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1607"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1803"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1809"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1909"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2004"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2004"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "4.4.0"
},
{
"fixed": "4.4.271"
}
]
},
{
"events": [
{
"introduced": "4.9.0"
},
{
"fixed": "4.9.271"
}
]
},
{
"events": [
{
"introduced": "4.14"
},
{
"fixed": "4.14.235"
}
]
},
{
"events": [
{
"introduced": "4.19"
},
{
"fixed": "4.19.193"
}
]
},
{
"events": [
{
"introduced": "5.4"
},
{
"fixed": "5.4.124"
}
]
},
{
"events": [
{
"introduced": "5.10"
},
{
"fixed": "5.10.42"
}
]
},
{
"events": [
{
"introduced": "5.12"
},
{
"fixed": "5.12.9"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-24588.json"