ID

VAR-202008-0420


CVE

CVE-2020-17497


TITLE

iNet wireless daemon Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-009556

DESCRIPTION

eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4. iNet wireless daemon (IWD) There is an unspecified vulnerability in.Information may be obtained and tampered with

Trust: 1.71

sources: NVD: CVE-2020-17497 // JVNDB: JVNDB-2020-009556 // VULHUB: VHN-170681

AFFECTED PRODUCTS

vendor:intelmodel:inet wireless daemonscope:lteversion:1.8

Trust: 1.0

vendor:intelmodel:wireless for open sourcescope:eqversion:1.8

Trust: 0.8

sources: JVNDB: JVNDB-2020-009556 // NVD: CVE-2020-17497

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-17497
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-009556
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202008-675
value: MEDIUM

Trust: 0.6

VULHUB: VHN-170681
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-17497
severity: MEDIUM
baseScore: 4.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-009556
severity: MEDIUM
baseScore: 4.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:N
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-170681
severity: MEDIUM
baseScore: 4.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-17497
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-009556
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-170681 // JVNDB: JVNDB-2020-009556 // CNNVD: CNNVD-202008-675 // NVD: CVE-2020-17497

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2020-17497

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202008-675

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202008-675

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009556

PATCH

title:Top Pageurl:https://www.intel.co.jp/content/www/jp/ja/homepage.html

Trust: 0.8

sources: JVNDB: JVNDB-2020-009556

EXTERNAL IDS

db:NVDid:CVE-2020-17497

Trust: 2.5

db:JVNDBid:JVNDB-2020-009556

Trust: 0.8

db:CNNVDid:CNNVD-202008-675

Trust: 0.7

db:VULHUBid:VHN-170681

Trust: 0.1

sources: VULHUB: VHN-170681 // JVNDB: JVNDB-2020-009556 // CNNVD: CNNVD-202008-675 // NVD: CVE-2020-17497

REFERENCES

url:https://lists.01.org/hyperkitty/list/iwd@lists.01.org/thread/4guxl4z6kzwwzinatghnjvaeuts3i7pg/

Trust: 1.5

url:https://nvd.nist.gov/vuln/detail/cve-2020-17497

Trust: 1.4

url:https://lists.01.org/hyperkitty/list/iwd%40lists.01.org/thread/4guxl4z6kzwwzinatghnjvaeuts3i7pg/

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-17497

Trust: 0.8

sources: VULHUB: VHN-170681 // JVNDB: JVNDB-2020-009556 // CNNVD: CNNVD-202008-675 // NVD: CVE-2020-17497

SOURCES

db:VULHUBid:VHN-170681
db:JVNDBid:JVNDB-2020-009556
db:CNNVDid:CNNVD-202008-675
db:NVDid:CVE-2020-17497

LAST UPDATE DATE

2024-11-23T21:59:07.625000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-170681date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-009556date:2020-11-12T07:56:25
db:CNNVDid:CNNVD-202008-675date:2020-08-28T00:00:00
db:NVDid:CVE-2020-17497date:2024-11-21T05:08:13.773

SOURCES RELEASE DATE

db:VULHUBid:VHN-170681date:2020-08-12T00:00:00
db:JVNDBid:JVNDB-2020-009556date:2020-11-12T07:56:25
db:CNNVDid:CNNVD-202008-675date:2020-08-12T00:00:00
db:NVDid:CVE-2020-17497date:2020-08-12T16:15:12.027