Advisory Published

cisco-sa-wifi-faf-22epcEWu: Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021

First published: Tue May 11 2021(Updated: )

On May 11, 2021, the research paper Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation was made public. This paper discusses 12 vulnerabilities in the 802.11 standard. One vulnerability is in the frame aggregation functionality, two vulnerabilities are in the frame fragmentation functionality, and the other nine are implementation vulnerabilities. These vulnerabilities could allow an attacker to forge encrypted frames, which could in turn enable the exfiltration of sensitive data from a targeted device. This advisory will be updated as additional information becomes available. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWu

Credit: These vulnerabilities were reported to Cisco by Dr. Mathy Vanhoef New York University Abu Dhabisupport during the handling these vulnerabilities

Affected SoftwareAffected VersionHow to fix
Cisco Products

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of cisco-sa-wifi-faf-22epcEWu?

    The severity of cisco-sa-wifi-faf-22epcEWu is high due to multiple vulnerabilities in the Wi-Fi 802.11 standard.

  • How do I fix cisco-sa-wifi-faf-22epcEWu?

    To mitigate cisco-sa-wifi-faf-22epcEWu, apply the latest patches provided by Cisco for affected products.

  • What vulnerabilities are included in cisco-sa-wifi-faf-22epcEWu?

    cisco-sa-wifi-faf-22epcEWu discusses vulnerabilities related to frame aggregation and fragmentation in the Wi-Fi standard.

  • Which Cisco products are affected by cisco-sa-wifi-faf-22epcEWu?

    cisco-sa-wifi-faf-22epcEWu affects various Cisco products that implement the 802.11 standard.

  • When was cisco-sa-wifi-faf-22epcEWu disclosed?

    cisco-sa-wifi-faf-22epcEWu was disclosed on May 11, 2021, following the publication of a research paper.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203