CVE-2020-26142 Details
Description
An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configuration.
A vulnerability exists in the OpenBSD kernel in version 6.6, where the implementations of WEP, WPA, WPA2, and WPA3 security protocols incorrectly treat fragmented frames as complete ones. This flaw can be exploited by an adversary to inject arbitrary network packets, regardless of the network configuration.
Users are advised to update to a version of OpenBSD that includes the patch for this vulnerability. Instructions for upgrading can be found on the OpenBSD website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openbsd openbsd | 6.6 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 3, 2021 | Modified Analysis | [email protected] |
| Oct 28, 2021 | CVE Modified | [email protected] |
| Sep 22, 2021 | Reanalysis | [email protected] |
| Jun 7, 2021 | Reanalysis | [email protected] |
| May 20, 2021 | Initial Analysis | [email protected] |
| May 11, 2021 | CVE Modified | [email protected] |