VDB

DEBIAN-CVE-2020-24588

DEBIAN-CVE-2020-24588 PUBLISHED CVSS 3.5 LOW

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets.

Risk Scores

CVSS v3.1
3.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
Debian:11linux0, 0, 0
Debian:12linux0, 0, 0
Debian:13linux0, 0, 0
Debian:12firmware-nonfree20200918-1, 0.43, 20161130-2
Debian:14firmware-nonfree0.41, 20210208-4, *
Debian:11firmware-nonfree0, 20260410-1, *
Debian:14linux0, 0, 0
Debian:13firmware-nonfree0, 0.1, 0.10

Timeline

  • May 11, 2021 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›