CVE-2020-26139 is a medium-severity vulnerability affecting the NetBSD 7.1 kernel and other products like Arista, Cisco, Debian, and Intel. It allows an attacker on the same network to cause a denial-of-service by exploiting an AP's improper forwarding of unauthenticated EAPOL frames. While the attack complexity is high, it can facilitate further client-side exploits. There is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has received some community discussion and media coverage as part of the broader FragAttacks vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1CPE matchmatch criteria | cpe:2.3:o:netbsd:netbsd:7.1:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:arista:c-100_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:arista:c-110_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:arista:c-120_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.