An issue exists on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
samsung galaxy i9305 firmware 4.4.4 |
||
arista c-250 firmware |
||
arista c-260 firmware |
||
arista c-230 firmware |
||
arista c-235 firmware |
||
arista c-200 firmware |
||
arista c-120 firmware |
||
arista c-130 firmware |
||
arista c-100 firmware |
||
arista c-110 firmware |
||
arista o-105 firmware |
||
arista w-118 firmware |
||
arista c-75 firmware - |
||
arista o-90 firmware - |
||
arista c-65 firmware - |
||
arista w-68 firmware - |
||
siemens scalance w700 ieee 802.11ax firmware |
||
siemens scalance w700 ieee 802.11n firmware |