3.3
CVSSv2

CVE-2020-26144

Published: 11/05/2021 Updated: 04/12/2021
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 295
Vector: AV:A/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samsung galaxy i9305 firmware 4.4.4

arista c-250 firmware

arista c-260 firmware

arista c-230 firmware

arista c-235 firmware

arista c-200 firmware

arista c-120 firmware

arista c-130 firmware

arista c-100 firmware

arista c-110 firmware

arista o-105 firmware

arista w-118 firmware

arista c-75 firmware -

arista o-90 firmware -

arista c-65 firmware -

arista w-68 firmware -

siemens scalance w700 ieee 802.11ax firmware

siemens scalance w700 ieee 802.11n firmware

Vendor Advisories

A flaw was found in the Linux kernel, where the WiFi implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (ex, LLC/SNAP) header for EAPOL The highest threat from this vulnerability is to integrity ...
On May 11, 2021, the research paper Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation was made public This paper discusses 12 vulnerabilities in the 80211 standard One vulnerability is in the frame aggregation functionality, two vulnerabilities are in the frame fragmentation functionality, and the other nine are impl ...
Severity Unknown Remote Unknown Type Unknown Description AVG-1879 linux 5122arch1-1 Medium Vulnerable ...

Mailing Lists

Hi, Several security issues in the 80211 implementations were found by Mathy Vanhoef (New York University Abu Dhabi), who has published all the details at papersmathyvanhoefcom/usenix2021pdf and wwwfragattackscom/ For Linux, we've developed the set of patches posted here: lorekernelorg/linux-wi ...