← Back to CVE intelligence
CVE intelligence

CVE-2020-24588

Vulnerability intelligence

Published May 11, 2021Sources checked Sep 12, 2026
3.5LOWCVSS out of 10
What this means

Review the available evidence

CVE-2020-24588 and is rated Low severity with a CVSS score of 3.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

CISA KEVNot listedBased on the latest collected catalog
EPSS3.5%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2020-24588?

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets.