CVE Vulnerabilities

CVE-2020-24458

Incomplete Cleanup

Published: Feb 17, 2021 | Modified: Feb 23, 2021
CVSS 3.x
5.2
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L
CVSS 2.x
4.1 MEDIUM
AV:A/AC:L/Au:S/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Incomplete cleanup in some Intel(R) PROSet/Wireless WiFi and Killer (TM) drivers before version 22.0 may allow a privileged user to potentially enable information disclosure and denial of service via adjacent access.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Proset/wireless_wifi Intel * 22.0 (excluding)

Potential Mitigations

References