On May 11, 2021, the Industry Consortium for Advancement of Security on the Internet (ICASI) announced the coordinated disclosure of a series of vulnerabilities related to the functionality of Wi-Fi devices. The complete list of vulnerabilities is listed below. Exploitation of these vulnerabilities may result in data exfiltration.
Of these issues listed below, only CVE-2020-24588 affects Juniper Networks Mist Access Points (APs). Successful exploitation of CVE-2020-24588 may allow an attacker to inject arbitrary network packets which could be used to spoof servers and conduct man-in-the-middle (MITM) attacks, in protected Wi-Fi networks, including WEP, WPA, WPA2, and WPA3.
This issue affects Juniper Networks Mist Access Point Firmware:
Mist Access Points are not affected by any of the other vulnerabilities listed below. However, additional protective measures have been implemented to defend against the vulnerabilities identified as CVE-2020-24586 and CVE-2020-24587.
All of these vulnerabilities also affect the Wi-Fi Mini-Physical Interface Module (Mini-PIM) for branch SRX Series Services Gateways.
This issue was discovered during external security research. The associated CVE IDs are as follows:
The following firmware versions for the Juniper Networks Mist Access Points have been updated to resolve this specific issue (CVE-2020-24588): 0.5.17562, 0.6.19227, 0.7.20564, 0.8.21602, 0.9.22801, and all subsequent releases.
Software releases or updates are available for download at https://support.juniper.net/support/downloads/ For Mist platform firmware updates please refer to https://www.mist.com/documentation/mist-security-advisory-fragattacks-and-faq
There are no known workarounds for this issue.
2021-05-11: Initial Publication. 2021-05-14: Updated fixed releases of firmware to include 0.9.22801.