Description
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
Published: 2021-05-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-18771 An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
History

Subscriptions

Arista C-100 C-100 Firmware C-110 C-110 Firmware C-120 C-120 Firmware C-130 C-130 Firmware C-200 C-200 Firmware C-230 C-230 Firmware C-235 C-235 Firmware C-250 C-250 Firmware C-260 C-260 Firmware C-65 C-65 Firmware C-75 C-75 Firmware O-105 O-105 Firmware O-90 O-90 Firmware W-118 W-118 Firmware W-68 W-68 Firmware
Redhat Enterprise Linux
Samsung Galaxy I9305 Galaxy I9305 Firmware
Siemens Scalance W700 Ieee 802.11ax Scalance W700 Ieee 802.11ax Firmware Scalance W700 Ieee 802.11n Scalance W700 Ieee 802.11n Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-14T08:49:08.532Z

Reserved: 2020-09-29T00:00:00.000Z

Link: CVE-2020-26144

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-11T20:15:08.837

Modified: 2026-04-14T09:16:25.173

Link: CVE-2020-26144

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-05-11T00:00:00Z

Links: CVE-2020-26144 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses