PT-2020-10033 · Wi Fi Alliance+2 · Wpa2+4
Published
2020-09-30
·
Updated
2021-07-21
·
CVE-2019-18991
CVSS v3.1
6.1
Medium
| Vector | AC:L/AV:A/A:N/C:L/I:L/PR:N/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
Atheros AR9132 version 3.60(AMX.8)
Atheros AR9283 version 1.85
Atheros AR9285 version 1.0.0.12NA
Description
A partial authentication bypass issue exists, allowing an attacker to send an unencrypted data frame to a WPA2-protected WLAN router. The packet is routed through the network, and if successful, a response is sent back as an encrypted frame. This could enable an attacker to discern information or potentially modify data.
Recommendations
For Atheros AR9132 version 3.60(AMX.8), consider restricting access to the network until a fix is available.
For Atheros AR9283 version 1.85, avoid using WPA2 protection until the issue is resolved.
For Atheros AR9285 version 1.0.0.12NA, as a temporary workaround, consider disabling the WLAN router's routing of unencrypted frames until a patch is available.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atheros Ar9132
Atheros Ar9283
Atheros Ar9285
Wlan
Wpa2