cbcvebase.
CVE-2020-26146
published 2021-05-11

CVE-2020-26146: An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet…

medium5.3CVSS 3.1
AVAACHPRNUINSUCNIHAN
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.

Affected

14 ranges
VendorProductVersion rangeFixed in
aristac-100_firmware< 11.0.0-3611.0.0-36
aristac-110_firmware< 11.0.0-3611.0.0-36
aristac-120_firmware< 11.0.0-3611.0.0-36
aristac-130_firmware< 11.0.0-3611.0.0-36
aristac-200_firmware< 11.0.0-3611.0.0-36
aristac-230_firmware< 10.0.1-3110.0.1-31
aristac-235_firmware< 10.0.1-3110.0.1-31
aristac-250_firmware< 10.0.1-3110.0.1-31
aristac-260_firmware< 10.0.1-3110.0.1-31
aristao-105_firmware< 11.0.0-3611.0.0-36
aristaw-118_firmware< 11.0.0-3611.0.0-36
googleandroid
samsunggalaxy_i9305_firmware
siemensscalance_w1750d_firmware< 8.7.1.38.7.1.3

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.3MEDIUM