PT-2011-1210 · Wi Fi Alliance · Wps

Publicado

2011-12-27

·

Atualizado

2013-01-15

·

CVE-2011-5053

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions WPS protocol (affected versions not specified)
Description The issue concerns the Wi-Fi Protected Setup (WPS) protocol, specifically when using the "external registrar" authentication method. It fails to properly inform clients about failed PIN authentication attempts, making it easier for remote attackers to discover the PIN value. This can lead to the discovery of the Wi-Fi network password or the reconfiguration of an access point by reading EAP-NACK messages. The vulnerability allows an attacker to obtain the WPA PSK-key by brute-forcing the PIN code through the WPS protocol, potentially enabling them to connect to the wireless network, change device configurations, or cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-10982
CVE-2011-5053

Produtos afetados

Wps