CVE-2020-26144
published 2021-05-11CVE-2020-26144: An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the…
PriorityP337medium6.5CVSS 3.1
AVAACLPRNUINSUCNIHAN
EPSS
4.91%
91.1th percentile
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | c-100_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-110_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-120_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-130_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-200_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-230_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | c-235_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | c-250_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | c-260_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | o-105_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | w-118_firmware | < 11.0.0-36 | 11.0.0-36 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1803 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_2004 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_cisco6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE FragAttacks
cisa_ics·2022-04-14
Siemens SCALANCE FragAttacks
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE FragAttacks
Last RevisedApril 14, 2022
Alert CodeICSA-22-104-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE family devices
- Vulnerabilities: Improper Authentication, Injection, Improper Validation of Integrity Check, Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker within Wi-Fi range to forge encrypted frames, which could result in sensitive data disclosure and traffic manipulation.
## 3. TECHNI
CISA ICS
Mitsubishi Electric GT25-WLAN (Update A)
cisa_ics·2022-04-12·CVSS 3.5
[LOW] Mitsubishi Electric GT25-WLAN (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric GT25-WLAN (Update A)
Last RevisedMay 12, 2022
Alert CodeICSA-22-102-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.5
- ATTENTION: Exploitable remotely
- Vendor: Mitsubishi Electric
- Equipment: Wireless LAN communication unit GT25-WLAN in GOT2000 Series GT25 or GT27
- Vulnerabilities: Improper Removal of Sensitive Information Before Storage or Transfer, Inadequate Encryption Strength, Missing Authentication for Critical Function, Injection, Improper Input Validation
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled IC
BSD
FreeBSD-SA-22:02.wifi: Multiple WiFi issues
bsd_advisories·2022-03-15·CVSS 3.5
CVE-2020-24588 [LOW] FreeBSD-SA-22:02.wifi: Multiple WiFi issues
FreeBSD-SA-22:02.wifi Security Advisory
The FreeBSD Project
Topic: Multiple WiFi issues
Category: core
Module: net80211
Announced: 2022-03-15
Affects: FreeBSD 12.x and FreeBSD 13.0
Corrected: 2021-11-19 00:01:25 UTC (stable/13, 13.0-STABLE)
2022-03-15 17:45:36 UTC (releng/13.0, 13.0-RELEASE-p8)
2022-02-15 16:05:49 UTC (stable/12, 12.3-STABLE)
2022-03-15 18:18:08 UTC (releng/12.3, 12.3-RELEASE-p3)
2022-03-15 18:17:30 UTC (releng/12.2, 12.2-RELEASE-p14)
CVE Name: CVE-2020-26147, CVE-2020-24588, CVE-2020-26144
Note: This issue is already fixed in FreeBSD 13.1-BETA1.
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD's net80211 kernel subsystem provi
CISA ICS
Hitachi ABB Power Grids TropOS
cisa_ics·2021-08-24·CVSS 3.5
[LOW] Hitachi ABB Power Grids TropOS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi ABB Power Grids TropOS
Last RevisedAugust 24, 2021
Alert CodeICSA-21-236-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Low attack complexity
- Vendor: Hitachi ABB Power Grids
- Equipment: TropOS
- Vulnerabilities: Injection, Inadequate Encryption Strength, Missing Authentication for Critical Function, Improper Authentication, Improper Validation of Integrity Check Value, Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to direct a client that is connected to a TropOS Wi-Fi access point
Cisco
Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
vendor_cisco·2021-05-11·CVSS 6.5
CVE-2020-24586 [MEDIUM] CWE-345 Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
On May 11, 2021, the research paper Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation was made public. This paper discusses 12 vulnerabilities in the 802.11 standard. One vulnerability is in the frame aggregation functionality, two vulnerabilities are in the frame fragmentation functionality, and the other nine are implementation vulnerabilities. These vulnerabilities could allow an attacker to forge encrypted frames, which could in turn enable the exfiltration of sensitive data from a targeted device.
This advisory will be updated as additional information becomes available.
This advisory is available at the following link
Microsoft
Windows Wireless Networking Spoofing Vulnerability
vendor_msrc·2021-05-11·CVSS 6.5
CVE-2020-26144 [MEDIUM] Windows Wireless Networking Spoofing Vulnerability
Windows Wireless Networking Spoofing Vulnerability
Windows Wireless Networking: Windows Wireless Networking
MITRE Corporation: MITRE Corporation
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003174
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003171
Reference: https://support.microsoft.com/help/5003171
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003169
Reference: https://support.microsoft.com/help/5003169
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003173
Reference: https://support.microsoft.com/he
Red Hat
kernel: accepting unencrypted A-MSDU frames that start with RFC1042 header
vendor_redhat·2021-05-11·CVSS 6.5
CVE-2020-26144 [MEDIUM] CWE-290 kernel: accepting unencrypted A-MSDU frames that start with RFC1042 header
kernel: accepting unencrypted A-MSDU frames that start with RFC1042 header
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
A flaw was found in the Linux kernel, where the WiFi implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (ex., LLC/SNAP) header for EAPOL. The highest threat from this vulnerability is to integrity.
Mitigation: Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Prod
Cisco
Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
vendor_cisco·CVSS 3.1
CVE-2020-26144 Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
CVE-2020-26144: Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
On May 11, 2021, the research paper Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation was made public. This paper discusses 12 vulnerabilities in the 802.11 standard. One vulnerability is in the frame aggregation functionality, two vulnerabilities are in the frame fragmentation functionality, and the other nine are implementation vulnerabilities. These vulnerabilities could allow an attacker to forge encrypted frames, which could in turn enable the exfiltration of sensitive data from a targeted device. This advisory will be updated as additional information becomes available. This advisory is available at the
GHSA
GHSA-89fj-xvf5-gc78: An issue was discovered on Samsung Galaxy S3 i9305 4
ghsa_unreviewed·2022-05-24
CVE-2020-26144 [MEDIUM] CWE-20 GHSA-89fj-xvf5-gc78: An issue was discovered on Samsung Galaxy S3 i9305 4
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
OSV
CVE-2020-26144: An issue was discovered on Samsung Galaxy S3 i9305 4
osv·2021-05-11·CVSS 6.5
CVE-2020-26144 [MEDIUM] CVE-2020-26144: An issue was discovered on Samsung Galaxy S3 i9305 4
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
No detection rules found.
No public exploits indexed.
HackerOne
Fragmentation and Aggregation Flaws in Wi-Fi
hackerone·2021-07-23·CVSS 5.3
CVE-2020-26140 [MEDIUM] Fragmentation and Aggregation Flaws in Wi-Fi
Fragmentation and Aggregation Flaws in Wi-Fi
I discovered three design flaws in the Wi-Fi standard and widespread related implementation flaws ([see GitHub overview and test tool](https://github.com/vanhoefm/fragattacks#fragattacks-fragmentation--aggregation-attacks)). **Here I'll specifically cover open source software**. These findings have not received bug bounties from other sources.
# Implementation flaws allowing trivial packet injection
- [CVE-2020-26140](https://nvd.nist.gov/vuln/detail/CVE-2020-26140): Accepting plaintext data frames in a protected network. This allows trivial packet injection. On a Linux client, the AWUS036H network card is vulnerable and two out of four Linux-based **home routers** were vulnerable. On **NetBSD access points**, three out of four tested networ
Qualys
Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
blogs_qualys·2021-05-11·CVSS 9.9
CVE-2021-31181 [CRITICAL] Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
## Microsoft Patch Tuesday – May 2021
Microsoft patched 55 CVEs in their May 2021 Patch Tuesday release, of which 4 are rated as critical severity. Three 0-day vulnerability patches were included in the release. As of this publication date, none have been exploited.
Qualys released 12 QIDs on the same day, providing vulnerability detection and patch management coverage (where applicable) for all 55 CVEs and the related KBs.
## Critical Microsoft vulnerabilities patched:
CVE-2021-31181 – SharePoint Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in SharePoint (CVE-2021-31181). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 8.8 by the vendor.
CVE-2021-31166 – HTTP Protocol Stack Remote Code
Crowdstrike
May 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
May 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
http://www.openwall.com/lists/oss-security/2021/05/11/12https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdfhttps://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.mdhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWuhttps://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63https://www.fragattacks.comhttp://www.openwall.com/lists/oss-security/2021/05/11/12https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdfhttps://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.mdhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWuhttps://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63https://www.fragattacks.comhttps://cert-portal.siemens.com/productcert/html/ssa-019200.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-913875.html
2021-05-11
Published