vanhoefm / fragattacks

Other
1.24k stars 185 forks source link

CVE-2020-24588 #21

Closed D3adP3nguin closed 3 years ago

D3adP3nguin commented 3 years ago

For the A-MSDU ping tests, if the CMD: amsdu-inject passes but the CMD: ping I,E --amsdu fails, would this mean that CVE-2020-24588 is been successfully patched?

vanhoefm commented 3 years ago

From the documentation:

D3adP3nguin commented 3 years ago

So if our device does support non-SPP A-MSDU frames and I'm able to see the raw ICMP payload from the test CMD ping I,E --amsdu what is that supposed to tell me about the device?

vanhoefm commented 3 years ago

If ping I,E --amsdu results in a ping request (in wireshark running on the device being tested) then that confirms that the device supports non-SPP A-MSDU frames. I don't know why your device is not responding to this ping request (if it responds then the test ping I,E --amsdu should succeed).