Vulnerability · NVD
CVE-2020-26146
CVE-2020-26146 : medium severity (CVSS 5.3). No tracked catalog app is linked to this CVE.
- Severity (CVSS)
- 5.3
- Exploitation
- 5.6 %
- Tracked apps
- 0
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Show raw CVSS vector
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Android Fixed in October 2021 patch level
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.