Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Galaxy_i9305_firmware
(Samsung)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 3 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-05-11 | CVE-2020-26145 | An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration. | Galaxy_i9305_firmware, 6gk5763\-1al00\-3aa0_firmware, 6gk5763\-1al00\-3da0_firmware, 6gk5763\-1al00\-7da0_firmware, 6gk5766\-1ge00\-3da0_firmware, 6gk5766\-1ge00\-3db0_firmware, 6gk5766\-1ge00\-7da0_firmware, 6gk5766\-1ge00\-7db0_firmware, 6gk5766\-1ge00\-7ta0_firmware, 6gk5766\-1ge00\-7tb0_firmware, 6gk5766\-1je00\-3da0_firmware, 6gk5766\-1je00\-7da0_firmware, 6gk5766\-1je00\-7ta0_firmware | 6.5 | ||
2021-05-11 | CVE-2020-26146 | An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design. | C\-100_firmware, C\-110_firmware, C\-120_firmware, C\-130_firmware, C\-200_firmware, C\-230_firmware, C\-235_firmware, C\-250_firmware, C\-260_firmware, C\-65_firmware, C\-75_firmware, O\-105_firmware, O\-90_firmware, W\-118_firmware, W\-68_firmware, Galaxy_i9305_firmware, Scalance_w1700_ieee_802\.11ac_firmware, Scalance_w1750d_firmware, Scalance_w700_ieee_802\.11n_firmware | 5.3 | ||
2021-05-11 | CVE-2020-26144 | An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration. | C\-100_firmware, C\-110_firmware, C\-120_firmware, C\-130_firmware, C\-200_firmware, C\-230_firmware, C\-235_firmware, C\-250_firmware, C\-260_firmware, C\-65_firmware, C\-75_firmware, O\-105_firmware, O\-90_firmware, W\-118_firmware, W\-68_firmware, Galaxy_i9305_firmware, Scalance_w700_ieee_802\.11ax_firmware, Scalance_w700_ieee_802\.11n_firmware | 6.5 |