5.3

CVE-2020-26146

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SamsungGalaxy I9305 Firmware Version4.4.4
   SamsungGalaxy I9305 Version-
AristaC-250 Firmware Version < 10.0.1-31
   AristaC-250 Version-
AristaC-260 Firmware Version < 10.0.1-31
   AristaC-260 Version-
AristaC-230 Firmware Version < 10.0.1-31
   AristaC-230 Version-
AristaC-235 Firmware Version < 10.0.1-31
   AristaC-235 Version-
AristaC-200 Firmware Version < 11.0.0-36
   AristaC-200 Version-
AristaC-120 Firmware Version < 11.0.0-36
   AristaC-120 Version-
AristaC-130 Firmware Version < 11.0.0-36
   AristaC-130 Version-
AristaC-100 Firmware Version < 11.0.0-36
   AristaC-100 Version-
AristaC-110 Firmware Version < 11.0.0-36
   AristaC-110 Version-
AristaO-105 Firmware Version < 11.0.0-36
   AristaO-105 Version-
AristaW-118 Firmware Version < 11.0.0-36
   AristaW-118 Version-
AristaC-75 Firmware Version-
   AristaC-75 Version-
AristaO-90 Firmware Version-
   AristaO-90 Version-
AristaC-65 Firmware Version-
   AristaC-65 Version-
AristaW-68 Firmware Version-
   AristaW-68 Version-
SiemensScalance W1750d Firmware Version < 8.7.1.3
   SiemensScalance W1750d Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.05% 0.768
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 1.6 3.6
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 2.9 5.5 2.9
AV:A/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.