CVE-2020-26146
published 2021-05-11CVE-2020-26146: An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet…
PriorityP431medium5.3CVSS 3.1
AVAACHPRNUINSUCNIHAN
EPSS
5.62%
92.0th percentile
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista | c-100_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-110_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-120_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-130_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-200_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | c-230_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | c-235_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | c-250_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | c-260_firmware | < 10.0.1-31 | 10.0.1-31 |
| arista | o-105_firmware | < 11.0.0-36 | 11.0.0-36 |
| arista | w-118_firmware | < 11.0.0-36 | 11.0.0-36 |
| android | — | — | |
| samsung | galaxy_i9305_firmware | — | — |
| siemens | scalance_w1750d_firmware | < 8.7.1.3 | 8.7.1.3 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_cisco6.5MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE FragAttacks
cisa_ics·2022-04-14
Siemens SCALANCE FragAttacks
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE FragAttacks
Last RevisedApril 14, 2022
Alert CodeICSA-22-104-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE family devices
- Vulnerabilities: Improper Authentication, Injection, Improper Validation of Integrity Check, Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker within Wi-Fi range to forge encrypted frames, which could result in sensitive data disclosure and traffic manipulation.
## 3. TECHNI
CISA ICS
Mitsubishi Electric GT25-WLAN (Update A)
cisa_ics·2022-04-12·CVSS 3.5
[LOW] Mitsubishi Electric GT25-WLAN (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric GT25-WLAN (Update A)
Last RevisedMay 12, 2022
Alert CodeICSA-22-102-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.5
- ATTENTION: Exploitable remotely
- Vendor: Mitsubishi Electric
- Equipment: Wireless LAN communication unit GT25-WLAN in GOT2000 Series GT25 or GT27
- Vulnerabilities: Improper Removal of Sensitive Information Before Storage or Transfer, Inadequate Encryption Strength, Missing Authentication for Critical Function, Injection, Improper Input Validation
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled IC
Android
CVE-2020-26146: WLAN
vendor_android·2021-10-01·CVSS 5.3
CVE-2020-26146 [MEDIUM] CVE-2020-26146: WLAN
Android Security Bulletin 2021-10-01
CVE: CVE-2020-26146
Severity: HIGH
Component: WLAN
References: A-175626808
QC-CR#2860242
QC-CR#2874369
CISA ICS
Hitachi ABB Power Grids TropOS
cisa_ics·2021-08-24·CVSS 3.5
[LOW] Hitachi ABB Power Grids TropOS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi ABB Power Grids TropOS
Last RevisedAugust 24, 2021
Alert CodeICSA-21-236-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Low attack complexity
- Vendor: Hitachi ABB Power Grids
- Equipment: TropOS
- Vulnerabilities: Injection, Inadequate Encryption Strength, Missing Authentication for Critical Function, Improper Authentication, Improper Validation of Integrity Check Value, Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to direct a client that is connected to a TropOS Wi-Fi access point
Red Hat
kernel: reassembling encrypted fragments with non-consecutive packet numbers
vendor_redhat·2021-05-11·CVSS 5.3
CVE-2020-26146 [MEDIUM] CWE-307 kernel: reassembling encrypted fragments with non-consecutive packet numbers
kernel: reassembling encrypted fragments with non-consecutive packet numbers
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
A vulnerability was found in Linux kernel, where the WiFi implementation reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP
Cisco
Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
vendor_cisco·2021-05-11·CVSS 6.5
CVE-2020-24586 [MEDIUM] CWE-345 Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
On May 11, 2021, the research paper Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation was made public. This paper discusses 12 vulnerabilities in the 802.11 standard. One vulnerability is in the frame aggregation functionality, two vulnerabilities are in the frame fragmentation functionality, and the other nine are implementation vulnerabilities. These vulnerabilities could allow an attacker to forge encrypted frames, which could in turn enable the exfiltration of sensitive data from a targeted device.
This advisory will be updated as additional information becomes available.
This advisory is available at the following link
Cisco
Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
vendor_cisco·CVSS 3.1
CVE-2020-26146 Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
CVE-2020-26146: Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021
On May 11, 2021, the research paper Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation was made public. This paper discusses 12 vulnerabilities in the 802.11 standard. One vulnerability is in the frame aggregation functionality, two vulnerabilities are in the frame fragmentation functionality, and the other nine are implementation vulnerabilities. These vulnerabilities could allow an attacker to forge encrypted frames, which could in turn enable the exfiltration of sensitive data from a targeted device. This advisory will be updated as additional information becomes available. This advisory is available at the
GHSA
GHSA-pwgj-jw9h-pg74: An issue was discovered on Samsung Galaxy S3 i9305 4
ghsa_unreviewed·2022-05-24
CVE-2020-26146 [MEDIUM] CWE-20 GHSA-pwgj-jw9h-pg74: An issue was discovered on Samsung Galaxy S3 i9305 4
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
OSV
CVE-2020-26146: An issue was discovered on Samsung Galaxy S3 i9305 4
osv·2021-05-11·CVSS 5.3
CVE-2020-26146 [MEDIUM] CVE-2020-26146: An issue was discovered on Samsung Galaxy S3 i9305 4
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2021/05/11/12https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdfhttps://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.mdhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWuhttps://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63https://www.fragattacks.comhttp://www.openwall.com/lists/oss-security/2021/05/11/12https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdfhttps://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.mdhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wifi-faf-22epcEWuhttps://www.arista.com/en/support/advisories-notices/security-advisories/12602-security-advisory-63https://www.fragattacks.comhttps://cert-portal.siemens.com/productcert/html/ssa-019200.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-913875.html
2021-05-11
Published