PT-2023-8665 · Google+6 · Android+7

Héloïse Gollier

+1

·

Published

2023-07-08

·

Updated

2025-02-03

·

CVE-2023-52160

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions wpa supplicant versions through 2.10
Description The issue is related to the implementation of PEAP in wpa supplicant, which allows authentication bypass. For a successful attack, wpa supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap peap decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks. Up to 2.3 billion user devices may be exposed to this issue, including Android, Linux, and ChromeOS devices.
Recommendations For wpa supplicant versions through 2.10, consider disabling the use of PEAP until a patch is available. Restrict access to Enterprise Wi-Fi networks to minimize the risk of exploitation. Avoid using configurations that do not verify the network's TLS certificate during Phase 1 authentication. As a temporary workaround, consider configuring wpa supplicant to verify the network's TLS certificate during Phase 1 authentication to prevent authentication bypass.

Exploit

Fix

Improper Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

ALSA-2024:2517
AZL-35457
AZL-35483
BDU:2024-01426
CVE-2023-52160
DLA-3743-1
INFSA-2024_2517
MGASA-2024-0053
OPENSUSE-SU-2024:13694-1
OPENSUSE-SU-2024_0764-1
OPENSUSE-SU-2024_3354-1
RHSA-2024:2517
RHSA-2024_2517
RLSA-2024:2517
ROSA-SA-2025-2577
SUSE-SU-2024:0764-1
SUSE-SU-2024:0764-2
SUSE-SU-2024:0818-1
SUSE-SU-2024:0819-1
SUSE-SU-2024:3354-1
SUSE-SU-2024_0764-1
SUSE-SU-2024_0818-1
SUSE-SU-2024_0819-1
SUSE-SU-2024_3354-1
SUSE-SU-2025:20089-1

Affected Products

Almalinux
Android
Astra Linux
Chrome Os
Red Hat
Red Os
Rocky Linux
Suse