Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-52424

Опубликовано: 17 мая 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.4

Описание

The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.

РелизСтатусПримечание
devel

deferred

esm-infra-legacy/trusty

deferred

esm-infra/bionic

deferred

esm-infra/focal

deferred

esm-infra/xenial

deferred

focal

ignored

end of standard support, was deferred
jammy

deferred

mantic

ignored

end of life, was deferred [2024-11-13]
noble

deferred

oracular

ignored

end of life, was deferred

Показывать по

EPSS

Процентиль: 44%
0.00214
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
больше 1 года назад

The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.

CVSS3: 7.4
nvd
больше 1 года назад

The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.

CVSS3: 7.4
github
больше 1 года назад

The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.

CVSS3: 8.8
fstec
больше 1 года назад

Уязвимость реализации стандарта Wi-Fi IEEE 802.11, связанная с недостаточной защитой служебных данных при обработке SSID-идентификатора, позволяющая нарушителю выполнить перехват трафика путём подмены точки доступа

EPSS

Процентиль: 44%
0.00214
Низкий

7.4 High

CVSS3