PT-2023-2034 · Unknown+1 · Ieee 802.11+1

CVE-2022-47522

·

Publicado

2023-03-28

·

Atualizado

2023-09-07

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IEEE 802.11 specifications through 802.11ax
Description The issue allows physically proximate attackers to intercept target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key. The vulnerability can be exploited to bypass encryption in wireless networks and may be used to intercept traffic from isolated clients.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Inadequate Encryption Strength

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01751
CVE-2022-47522
FREEBSD-SA-23_11

Produtos afetados

Freebsd
Ieee 802.11