Vulnerability

CVE-2020-26145

Component: WIFI
Location: OS
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

6.5

Severity (Android)

N/A

Chipsets

15

Devices

462

Affected Hardware

NameAlso known asManufacturer
MSM8208
Snapdragon 208
Qualcomm
MSM8937
Snapdragon 430
Qualcomm
MSM8940
Snapdragon 435
Qualcomm
MSM8952
Snapdragon 617
Qualcomm
MSM8953
Snapdragon 625
Qualcomm
SDM636
Snapdragon 636
Qualcomm
MSM8956
Snapdragon 650
Qualcomm
MSM8976
Snapdragon 652
Qualcomm
SM6150
Snapdragon 675
Qualcomm
SM7325
Snapdragon 778G
Qualcomm
15 of 15 row(s) shown.

Rows per page

Page 1 of 2

Timeline

Introduced (est):
Jan 1, 2014
Reported:
Dec 13, 2020
Advisory Published:
Aug 2, 2021
CVE Published:
May 11, 2021
Android Patch Level:
Oct 2021
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter