All Wifi Devices Can Be Attacked by FragAttacks Vulnerabilities
Three of these errors are due to the Wi-Fi 802.11 standard design in frame aggregation and frame fragmentation affecting most devices, while others are due to programming in Wifi products. .
'Tests indicate that every Wifi product is affected by at least one vulnerability, and most products are affected by several vulnerabilities.
The discovered vulnerabilities affect all modern Wi-Fi security protocols, including WPA3. Even Wifi's native security protocol, known as WEP, is affected.
This means that some of the newly discovered design flaws have existed since its release in 1997' – information security expert Vanhoef.
Attackers who abuse these design flaws must be within Wi-Fi range of the devices they want to attack in order to steal sensitive user data and execute malicious code.
Impact of the FragAttacks vulnerability
Fortunately, the Vanhoef expert discovered additional 'design flaws that are difficult to abuse because doing so requires user interaction or is only possible when using uncommon network settings'.
The programming flaws behind some FragAttacks vulnerabilities are trivial to exploit, however, they can allow attackers to easily abuse unpatched Wifi products.
FragAttacks CVE related to Wifi design flaws include:
- CVE-2020-24588
- CVE-2020-24587
- CVE-2020-24586
The Wi-Fi implementation vulnerabilities are assigned the following CVEs:
- CVE-2020-26145
- CVE-2020-26144
- CVE-2020-26140
- CVE-2020-26143
Other implementation errors detected by Vanhoef include:
- CVE-2020-26139
- CVE-2020-26147
- CVE-2020-26142
- CVE-2020-26141
The researcher also made a video showing how attackers can take over an unpatched Windows 7 system inside the target's local network.
Security updates have been released by several vendors
The Industry Association for the Advancement of the Internet (ICASI) says vendors are developing patches for their products to mitigate FragAttacks.
Cisco Systems, HPE / Aruba Networks, Juniper Networks, Sierra Wireless, and Microsoft have released FragAttacks security updates and advisory.
These security updates are all monitored by ICASI and the Wifi Alliance.
The Wifi Alliance said: 'There is no evidence that the vulnerabilities are maliciously used to target Wifi users, and the risks are reduced through periodic device updates when significant traffic is detected. suspect or improve compliance with the recommended security implementation'.
Additionally, Wifi Alliance notes that Wifi users should ensure they have installed the latest recommended updates from device manufacturers.
Minimize FragAttacks
If your device vendor hasn't released a security update to address the FragAttacks errors, there are still ways to reduce vulnerability:
- Make sure all websites and online services you visit use HTTPS
- Use the strongest, unique password
- Do not visit the dark web
Over the past four years, Vanhoef has also discovered KRACK and Dragonblood attacks, which allow attackers to observe encrypted network traffic exchanged between connected Wifi devices, crack Wifi network passwords. , spoofing web traffic by injecting malicious packets and stealing sensitive information.
You should read it
- Learn about WPA3, the latest WiFi security standard today
- The new WPA3 WiFi standard was officially released
- What is a WiFi Karma attack?
- Discover new ways to hack WPA3 protected WiFi passwords
- Difference between WiFi 5, WiFi 6 and WiFi 6E
- What is the newly announced WPA3 WiFi security protocol?
- What is WiFi 6E? How is WiFi 6E different from WiFi 6?
- What is WiFi 6? What is WiFi 6E? Things you need to know about WiFi 6 and WiFi 6E
May be interested
- 6 best Wifi wave-enabled devices and Wifi wave amplifiers in 2018wifi tuner, wifi extension or wifi amplifier are devices that relay and re-broadcast wifi waves with almost the same intensity as the original equipment and help expand the coverage range.
- Discover new ways to hack WPA3 protected WiFi passwordsearlier this month, it was the cyber security team that found dragonblood to continue to release two more serious vulnerabilities that could allow an attacker to easily hack the target wifi password.
- Difference between WiFi 5, WiFi 6 and WiFi 6Ehaving fast wifi has become indispensable in our daily lives. from surfing the internet and working from home to online gaming and streaming netflix, it all depends on a strong wifi connection.
- Why do 802.11b devices slow down your WiFi network?wifi has changed the way we connect to the internet. allowing users to access the internet via radio waves, wifi-enabled users connect to the world wide web without a cable connection.
- Which phones support Wifi 6?finally, the wi-fi alliance trade alliance group has officially issued wifi 6 certification to manufacturers. this means users will experience the latest in wifi technology, with the fastest speeds ever.
- What is WiFi 6E? How is WiFi 6E different from WiFi 6?technology is always developing very quickly, when wifi 6 was just popular, the new standard wifi 6e was officially launched. so what is wifi 6e? wifi 6e is nothing different than wifi 6, invite you to find out.
- 9 best free wifi playback software and download linkhere is a list of the 9 best wifi applications for wifi sharing on your computer for other devices around when solving problems without wifi router. all these wifi broadcast software are free.
- What is WiFi Marketing? What is the benefit of WiFi Marketing?social wifi marketing is a form of brand advertising when they access a free wifi network. the image of the brand, the product will appear on the interface for a certain period of time, so that users can capture an overview of the product's information.
- 16 new security vulnerabilities can cause systems using Microsoft software to be attackedin addition to warnings about security vulnerabilities in pan-os being used to attack systems, in april, the department of information security (ministry of information and communications) also recommended that units pay attention to 16 high-impact vulnerabilities. , serious in microsoft products.
- Why are WiFi waves often weak in rooms in the corner?one of the weaknesses of wifi is that the wave quality is not stable when receiving devices and transmitters are separated by many walls.