An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.
References
Configurations
Information
Published : 2021-05-11 20:15
Updated : 2021-10-28 15:15
NVD link : CVE-2020-26139
Mitre link : CVE-2020-26139
JSON object : View
Products Affected
netbsd
- netbsd
CWE
CWE-287
Improper Authentication
