PT-2024-1721 · Unknown · Inet Wireless Daemon
Mathy Vanhoef
·
Published
2024-01-29
·
Updated
2024-08-29
·
CVE-2023-52161
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iNet wireless daemon (IWD) versions prior to 2.14
Description
The issue allows attackers to gain unauthorized access to a protected Wi-Fi network by skipping certain messages in the EAPOL handshake and sending a message with an all-zero key. This can be done by exploiting the Access Point functionality in the eapol auth key handle function in eapol.c. The vulnerability affects private networks and is particularly dangerous for PCs running Linux, as it exposes home networks using a Linux device as an access point, allowing unauthorized access without a password.
Recommendations
For versions prior to 2.14, update to version 2.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable Access Point functionality until a patch is available. Avoid using the
eapol auth key handle function in the affected API endpoint until the issue is resolved.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Inet Wireless Daemon