CVE-2020-26146
Summary
| CVE | CVE-2020-26146 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-11 20:15:00 UTC |
| Updated | 2021-12-06 13:45:00 UTC |
| Description | An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 2021 |
CISCO |
tools.cisco.com |
|
| FragAttacks: Security flaws in all Wi-Fi devices |
MISC |
www.fragattacks.com |
|
| Security Advisory 0063 - Arista |
MISC |
www.arista.com |
|
| fragattacks/SUMMARY.md at master · vanhoefm/fragattacks · GitHub |
MISC |
github.com |
|
| cert-portal.siemens.com/productcert/pdf/ssa-913875.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| oss-security - various 802.11 security issues - fragattacks.com |
MLIST |
www.openwall.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159403 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9459)
- 159492 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-4356)
- 239816 Red Hat Update for kernel security (RHSA-2021:4356)
- 239879 Red Hat Update for kernel-rt (RHSA-2021:4140)
- 390248 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2021-0035)
- 43828 HPE ArubaOS Multiple Vulnerabilities (ARUBA-PSA-2021-011)
- 591035 Siemens SCALANCE FragAttacks Multiple Vulnerabilities (ICSA-22-104-04) (SSA-913875)
- 591104 Mitsubishi Electric GT25-WLAN (Update A) Multiple Vulnerabilities (ICSA-22-102-04)
- 591150 Hitachi ABB Power Grids TropOS Multiple Vulnerabilities (ICSA-21-236-01,9AKK107992A4463)
- 610373 Google Android Devices October 2021 Security Patch Missing
- 610381 Google Android November 2021 Security Patch Missing for Huawei EMUI
- 610383 Google Android November 2021 Security Patch Missing for LGE
- 671441 EulerOS Security Update for kernel (EulerOS-SA-2022-1366)
- 671703 EulerOS Security Update for kernel (EulerOS-SA-2022-1735)
- 940265 AlmaLinux Security Update for kernel (ALSA-2021:4356)