Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2020-26145

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.

SeverityMEDIUM
CVSS6.5
CWECWE-20
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco Webex Room Phone cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco TelePresence Endpoint Software (TC/CE) cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco TelePresence cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco IP phone cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco IP Phones with Multiplatform Firmware cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco Business Wireless Access Point Software cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco Aironet Access Point Software (IOS XE Controller) cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln
Cisco Aironet Access Point Software cisco-sa-wifi-faf-22epcEWu Cisco OpenVuln