CVE-2020-24588
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenti...
Public exploit available. Not confirmed exploited in the wild yet. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
What it is
From the CVE record
SCALANCE W-700 IEEE 802.11n family before V6.6.0 are affected by multiple vulnerabilities. Siemens has released a new version for SCALANCE W-700 IEEE 802.11n family and recommends to update to the latest version.
In plain language
No plain-language summary for this CVE yet.
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
1 source with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
3.5% chance of exploitation activity in the next 30 days, which ranks it in the 89th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
A public exploit existed 38 days before the patch.
- OpenVAS check added
- Patch availablerecord updated
- Public exploit / PoCsource: other
- Publishedweakness classified, att&ck mapped
Affected products
- Cisco IP Conference Phone 8832Networking Infrastructure
- Cisco IP Phone 6861 with MultiplatformNetworking Infrastructure
- Cisco IP Phone 8865Networking Infrastructure
- Cisco IP Phone 8861 Running Third-Party Call Control (3PCC) SoftwareNetworking Infrastructure
- Cisco IP Phone 8821Networking Infrastructure
- Webex RoomNetworking Infrastructure
- Webex DeskNetworking Infrastructure
- Webex BoardNetworking Infrastructure
- scalance w1748-1 firmwareICS / OT / IoT
- scalance w1750d firmwareICS / OT / IoT
- scalance w1788-1 firmwareICS / OT / IoT
- scalance w1788-2 firmwareICS / OT / IoT
- scalance w1788-2ia firmwareICS / OT / IoT
- scalance w721-1 firmwareICS / OT / IoT
- scalance w722-1 firmwareICS / OT / IoT
- scalance w734-1 firmwareICS / OT / IoT
- ac 8260 firmwareHardware Firmware
- ac 8265 firmwareHardware Firmware
- ac 9260 firmwareHardware Firmware
- ac 9560 firmwareHardware Firmware
- killer ac 1550 firmwareHardware Firmware
- killer wi-fi 6 ax1650 firmwareHardware Firmware
- killer wi-fi 6e ax1675 firmwareHardware Firmware
- proset ac 3165 firmwareHardware Firmware
- c-100 firmwareNetworking Infrastructure
- c-110 firmwareNetworking Infrastructure
- c-120 firmwareNetworking Infrastructure
- c-130 firmwareNetworking Infrastructure
- c-200 firmwareNetworking Infrastructure
- c-230 firmwareNetworking Infrastructure
- c-235 firmwareNetworking Infrastructure
- c-250 firmwareNetworking Infrastructure
- Windows 8.1Operating Systems / windows
- Windows Server 2008 Service Pack 2 (Server Core Installation)Operating Systems / windows
- Windows Server 2012 (Server Core installation)Operating Systems / windows
- Windows Server 2012 R2 (Server Core installation)Operating Systems / windows
- Windows Server 2008 R2 Service Pack 1Operating Systems / windows
- Windows RT 8.1Operating Systems / windows
- Windows 10 1607Operating Systems / windows
- Windows Server 2016 (Server Core installation)Operating Systems / windows
And 193 more affected products. See all after sign-in
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Scored 3.5 by NVD.
How it is reached
- Attack Vector AdjacentRequires access to the local network (e.g. same Wi-Fi, Bluetooth)
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction RequiredA user must click a link, open a file, or perform some action
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality NoneNo confidentiality impact
- Integrity LowData modification is possible but limited in scope or consequence
- Availability NoneNo availability impact
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
- openwall.com/lists/oss-security/2021/05/11/12&
- cert-portal.siemens.com/productcert/pdf/ssa-913875.pdf&
- cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24588&
And 84 more references. See all after sign-in
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Cisco Systems Inc., not every advisory. This one: public exploit.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI