Description
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Published: 2021-05-11
Score: 5.3 Medium
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-18773 An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
History

Subscriptions

Arista C-100 C-100 Firmware C-110 C-110 Firmware C-120 C-120 Firmware C-130 C-130 Firmware C-200 C-200 Firmware C-230 C-230 Firmware C-235 C-235 Firmware C-250 C-250 Firmware C-260 C-260 Firmware C-65 C-65 Firmware C-75 C-75 Firmware O-105 O-105 Firmware O-90 O-90 Firmware W-118 W-118 Firmware W-68 W-68 Firmware
Redhat Enterprise Linux
Samsung Galaxy I9305 Galaxy I9305 Firmware
Siemens Scalance W1700 Ieee 802.11ac Scalance W1700 Ieee 802.11ac Firmware Scalance W1750d Scalance W1750d Firmware Scalance W700 Ieee 802.11n Scalance W700 Ieee 802.11n Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-14T08:49:11.814Z

Reserved: 2020-09-29T00:00:00.000Z

Link: CVE-2020-26146

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-11T20:15:08.907

Modified: 2026-04-14T09:16:26.203

Link: CVE-2020-26146

cve-icon Redhat

Severity : Low

Publid Date: 2021-05-11T00:00:00Z

Links: CVE-2020-26146 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses