PT-2021-1510 · Samsung+9 · Samsung Galaxy S3+9

Mathy Vanhoef

·

Published

2021-05-11

·

Updated

2022-05-13

·

CVE-2020-26145

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified) Samsung Galaxy S3 i9305 version 4.4.4 Check Point GAiA (affected versions not specified)
Description The issue exists due to insufficient input validation in the implementation of WEP, WPA, WPA2, and WPA3 algorithms. This allows a remote attacker to inject arbitrary network packets, regardless of the network configuration, by exploiting the acceptance of second or subsequent broadcast fragments sent in plaintext and processing them as full unfragmented frames.
Recommendations For Linux kernel, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Samsung Galaxy S3 i9305 version 4.4.4, consider restricting access to the network until a patch is available. For Check Point GAiA, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4356
ALT-PU-2021-1917
ALT-PU-2021-1946
ALT-PU-2021-1948
ALT-PU-2021-1961
ALT-PU-2021-1990
ALT-PU-2021-2370
ALT-PU-2021-2672
ALT-PU-2021-2677
ALT-PU-2021-2678
ALT-PU-2021-2737
ALT-PU-2021-2751
ALT-PU-2022-1240
ASB-A-177910901
BDU:2021-03175
CESA-2021_4140
CESA-2021_4356
CVE-2020-26145
MGASA-2021-0257
MGASA-2021-0258
OESA-2021-1407
OPENSUSE-SU-2021:0843-1
OPENSUSE-SU-2021:0947-1
OPENSUSE-SU-2021:1975-1
OPENSUSE-SU-2021:1977-1
OPENSUSE-SU-2021_0843-1
OPENSUSE-SU-2021_0947-1
OPENSUSE-SU-2021_1975-1
OPENSUSE-SU-2021_1977-1
RHSA-2021:4140
RHSA-2021:4356
RHSA-2021_4140
RHSA-2021_4356
SUSE-SU-2021:1887-1
SUSE-SU-2021:1888-1
SUSE-SU-2021:1889-1
SUSE-SU-2021:1890-1
SUSE-SU-2021:1891-1
SUSE-SU-2021:1899-1
SUSE-SU-2021:1912-1
SUSE-SU-2021:1913-1
SUSE-SU-2021:1975-1
SUSE-SU-2021:1977-1
SUSE-SU-2021:2208-1
SUSE-SU-2021:2406-1
SUSE-SU-2021:2421-1
SUSE-SU-2021:2451-1
USN-4997-1
USN-4997-2
USN-4999-1
USN-5000-1
USN-5000-2
USN-5001-1
USN-5361-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Check Point Gaia
Linuxmint
Red Hat
Samsung Galaxy S3
Suse
Ubuntu