CVE-2010-4648 describes a vulnerability in the Linux kernel's orinoco_ioctl_set_auth function (drivers/net/wireless/orinoco/wext.c) before version 2.6.37, affecting the TKIP protection mechanism in wireless drivers. This flaw allows remote attackers on the same network to more easily read Wi-Fi frames, potentially gaining unauthorized access to the network. The vulnerability has a CVSS score of 3.3 (AV:A/AC:L/Au:N/C:P/I:N/A:N), indicating a low severity with local network access required and a potential for partial confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.36.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
2.6.36.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.36.1:*:*:*:*:*:*:* | ||
2.6.36.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.36.2:*:*:*:*:*:*:* | ||
2.6.36.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:2.6.36.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.