An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
Se detectó un problema en los dispositivos Samsung Galaxy S3 i9305 versión 4.4.4. Las implementaciones de WEP, WPA, WPA2 y WPA3 aceptan segundos fragmentos de transmisión (o posteriores) incluso cuando se envían en texto plano y los procesan como tramas completas no fragmentados. Un adversario puede abusar de esto para inyectar paquetes de red arbitrarios independientemente de la configuración de la red
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
| Attack Vector | ADJACENT_NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | HIGH |
| Availability Impact | NONE |
AV:A/AC:L/Au:N/C:N/I:P/A:N
| Access Vector | ADJACENT_NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | NONE |
| Integrity Impact | PARTIAL |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-20
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| samsung | galaxy_i9305_firmware | 4.4.4 | <built-in method update of dict object at 0x72a9b0a6ca40> | Operating System |
| siemens | 6gk5763-1al00-7da0_firmware | * | <built-in method update of dict object at 0x72a961eca600> | Operating System |
| siemens | 6gk5766-1ge00-7da0_firmware | * | <built-in method update of dict object at 0x72a961ec8d00> | Operating System |
| siemens | 6gk5766-1ge00-7db0_firmware | * | <built-in method update of dict object at 0x72a963c69f80> | Operating System |
| siemens | 6gk5766-1je00-7da0_firmware | * | <built-in method update of dict object at 0x72a9b0a6c7c0> | Operating System |
| siemens | 6gk5766-1ge00-7ta0_firmware | * | <built-in method update of dict object at 0x72a9b0a6cbc0> | Operating System |
| siemens | 6gk5766-1ge00-7tb0_firmware | * | <built-in method update of dict object at 0x72a961ec8440> | Operating System |
| siemens | 6gk5766-1je00-7ta0_firmware | * | <built-in method update of dict object at 0x72a961ec9900> | Operating System |
| siemens | 6gk5763-1al00-3aa0_firmware | * | <built-in method update of dict object at 0x72a961ecb640> | Operating System |
| siemens | 6gk5763-1al00-3da0_firmware | * | <built-in method update of dict object at 0x72a9b0a6ccc0> | Operating System |
| siemens | 6gk5766-1ge00-3da0_firmware | * | <built-in method update of dict object at 0x72a961ec8400> | Operating System |
| siemens | 6gk5766-1ge00-3db0_firmware | * | <built-in method update of dict object at 0x72a961ecb2c0> | Operating System |
| siemens | 6gk5766-1je00-3da0_firmware | * | <built-in method update of dict object at 0x72a961ecb900> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:samsung:galaxy_i9305_firmware:4.4.4:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:samsung:galaxy_i9305:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5763-1al00-7da0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5763-1al00-7da0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5766-1ge00-7da0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5766-1ge00-7da0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5766-1ge00-7db0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5766-1ge00-7db0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5766-1je00-7da0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5766-1je00-7da0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5766-1ge00-7ta0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5766-1ge00-7ta0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5766-1ge00-7tb0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5766-1ge00-7tb0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5766-1je00-7ta0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5766-1je00-7ta0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5763-1al00-3aa0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5763-1al00-3aa0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5763-1al00-3da0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5763-1al00-3da0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5766-1ge00-3da0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5766-1ge00-3da0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5766-1ge00-3db0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5766-1ge00-3db0:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:siemens:6gk5766-1je00-3da0_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:siemens:6gk5766-1je00-3da0:-:*:*:*:*:*:*:* |