cbcvebase.
CVE-2020-26145
published 2021-05-11

CVE-2020-26145: An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast…

PriorityP336medium6.5CVSS 3.1
AVAACLPRNUINSUCNIHAN
EPSS
3.52%
87.9th percentile
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.35-1 (forky)linux 6.12.35-1 (forky)
debianlinux< linux 5.10.46-1 (bookworm)linux 5.10.46-1 (bookworm)
googleandroid
linuxlinux
linuxlinux>= 98686cd21624c75a043e96812beadddf4f6f48e5 < 24900688ee47071aa6a61e78473999b5b80f042324900688ee47071aa6a61e78473999b5b80f0423
linuxlinux>= 98686cd21624c75a043e96812beadddf4f6f48e5 < d4b93f9c2f666011dcf810050ef60a6b8d06f186d4b93f9c2f666011dcf810050ef60a6b8d06f186
linuxlinux>= 98686cd21624c75a043e96812beadddf4f6f48e5 < 5fd5b8132b5de08c99eea003f7715ff2e361b0075fd5b8132b5de08c99eea003f7715ff2e361b007
linuxlinux>= 98686cd21624c75a043e96812beadddf4f6f48e5 < 80fda1cd7b0a1edd0849dc71403a070d0922118d80fda1cd7b0a1edd0849dc71403a070d0922118d
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 5.10.46-15.10.46-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 5.4.0-77.865.4.0-77.86
linuxlinux_kernel>= 0 < 4.4.0-223.2564.4.0-223.256
linuxlinux_kernel>= 6.13 < 6.15.46.15.4
linuxlinux_kernel>= 6.2 < 6.6.956.6.95
linuxlinux_kernel>= 6.7 < 6.12.356.12.35
samsunggalaxy_i9305_firmware
siemens6gk5763-1al00-3aa0_firmware< 1.21.2
siemens6gk5763-1al00-3da0_firmware< 1.21.2
siemens6gk5763-1al00-7da0_firmware< 1.21.2
siemens6gk5766-1ge00-3da0_firmware< 1.21.2
siemens6gk5766-1ge00-3db0_firmware< 1.21.2

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_cisco6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.