Vulnerability
CVE-2020-26145
Component: WIFI
Location: OS
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
Impact
Severity (Manufact.)
HIGH
Severity (NIST)
6.5
Severity (Android)
N/A
Chipsets
15
Devices
462
Affected Hardware
Name | Also known as | Manufacturer |
---|---|---|
MSM8208 | Snapdragon 208 | Qualcomm |
MSM8937 | Snapdragon 430 | Qualcomm |
MSM8940 | Snapdragon 435 | Qualcomm |
MSM8952 | Snapdragon 617 | Qualcomm |
MSM8953 | Snapdragon 625 | Qualcomm |
SDM636 | Snapdragon 636 | Qualcomm |
MSM8956 | Snapdragon 650 | Qualcomm |
MSM8976 | Snapdragon 652 | Qualcomm |
SM6150 | Snapdragon 675 | Qualcomm |
SM7325 | Snapdragon 778G | Qualcomm |
15 of 15 row(s) shown.
Rows per page
Page 1 of 2
Information reliability
The information on this website is intended to provide information on the big picture of chipset security and measure trends within the industry. Our information is obtained from several vantage points, checked for consistency, and automatically cross-referenced. However, this process may not always yield reliable information. Do not use the information on a particular vulnerability, chipset or device to verify your individual exposure in cases where inaccuracies are inacceptable, for instance to assess risks if you are a Politically Exposed Person.
Timeline
Introduced (est):
Jan 1, 2014
Reported:
Dec 13, 2020
Advisory Published:
Aug 2, 2021
CVE Published:
May 11, 2021
Android Patch Level:
Oct 2021