Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-52160

Опубликовано: 22 фев. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 6.5

Описание

The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

deferred

esm-infra-legacy/trusty

deferred

esm-infra-legacy/xenial

deferred

esm-infra/bionic

deferred

esm-infra/focal

deferred

esm-infra/xenial

ignored

end of ESM support, was deferred
focal

ignored

end of standard support, was deferred
jammy

deferred

mantic

ignored

end of life, was deferred

Показывать по

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 2 лет назад

The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.

CVSS3: 6.5
nvd
больше 2 лет назад

The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.

CVSS3: 6.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 6.5
debian
больше 2 лет назад

The implementation of PEAP in wpa_supplicant through 2.10 allows authe ...

suse-cvrf
почти 2 года назад

Security update for wpa_supplicant

6.5 Medium

CVSS3