CVE-2020-26145

medium

Description

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.

References

https://www.tenable.com/cyber-exposure/2021-threat-landscape-retrospective

https://www.fragattacks.com/

https://www.fragattacks.com

https://github.com/vanhoefm/fragattacks/blob/master/SUMMARY.md

https://cert-portal.siemens.com/productcert/pdf/ssa-913875.pdf

http://www.openwall.com/lists/oss-security/2021/05/11/12

Details

Source: Mitre, NVD

Published: 2021-05-11

Updated: 2022-05-13

Risk Information

CVSS v2

Base Score: 3.3

Vector: CVSS2#AV:A/AC:L/Au:N/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: Medium