PT-2024-1721 · Unknown · Inet Wireless Daemon

Mathy Vanhoef

·

Published

2024-01-29

·

Updated

2024-08-29

·

CVE-2023-52161

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions iNet wireless daemon (IWD) versions prior to 2.14
Description The issue allows attackers to gain unauthorized access to a protected Wi-Fi network by skipping certain messages in the EAPOL handshake and sending a message with an all-zero key. This can be done by exploiting the Access Point functionality in the eapol auth key handle function in eapol.c. The vulnerability affects private networks and is particularly dangerous for PCs running Linux, as it exposes home networks using a Linux device as an access point, allowing unauthorized access without a password.
Recommendations For versions prior to 2.14, update to version 2.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable Access Point functionality until a patch is available. Avoid using the eapol auth key handle function in the affected API endpoint until the issue is resolved.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

AZL-43933
AZL-44235
BDU:2024-01425
CVE-2023-52161
DLA-3738-1
DSA-5631-1

Affected Products

Inet Wireless Daemon