CISCO-SA-WIFI-FAF-22EPCEWU
On May 11, 2021, the research paper Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation was made public. This paper discusses 12 vulnerabilities in the 802.11 standard. One vulnerability is in the frame aggregation functionality, two vulnerabilities are in the frame fragmentation functionality, and the other nine are implementation vulnerabilities. These vulnerabilities could allow an attacker to forge encrypted frames, which could in turn enable the exfiltration of sensitive data from a targeted device. This advisory will be updated as additional information becomes available.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco TelePresence Endpoint Software (TC/CE) | ||
| Cisco IP Phones with Multiplatform Firmware | ||
| Cisco Aironet Access Point Software (IOS XE Controller) | ||
| Cisco Aironet Access Point Software | ||
| Cisco Business Wireless Access Point Software | ||
| Cisco Webex Room Phone |
Exploit Intelligence
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu (circl)
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html (circl)
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#fixes (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy32690 (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24420 (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy32680 (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24449 (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy36698 (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24425 (circl)
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24439 (circl)
…and 13 more exploits
Timeline
- May 11, 2021 CVE Published
- Dec 15, 2021 CVE Updated
References
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu advisory
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html url
- https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html#fixes url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy32690 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24420 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy32680 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24449 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvy36698 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24425 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24439 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24428 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24452 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx24456 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx60997 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx61001 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx61012 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx89821 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx61020 url
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvx62886 url
- https://papers.mathyvanhoef.com/usenix2021.pdf url
…and 3 more