Input validation error in IEEE 802.11 - CVE-2023-52424
Published: December 27, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to SSID confusion error in the IEEE 802.11 standard. A remote attacker can trick the victim into connecting to unintended or untrusted network with Home WEP, Home WPA3 SAE-loop, Enterprise 802.1X/EAP, Mesh AMPE, or FILS. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.
Affected software
Arista Wireless Access Points
Anolis OS
Fedora
libell
wpa_supplicant
wpa_supplicant-doc
hostapd
iwd
bluez
How to mitigate CVE-2023-52424
wpa_supplicant - update to 2.11-1
wpa_supplicant-doc - update to 2.11-1
hostapd - update to 2.11-1.fc40
wpa_supplicant - update to 2.11-1.fc40
iwd - addressed in versions 2.21-1.fc40, 2.21-1.fc41, 3.3-1.fc40, 3.3-1.fc41
bluez - addressed in versions 5.78-1.fc40, 5.78-1.fc41
External References
Related Security Bulletins
- SSID confusion in IEEE 802.11 standard
- Fedora 41 update for iwd, libell
- Fedora 40 update for iwd, libell
- Fedora 40 update for hostapd, wpa_supplicant
- Fedora 40 update for bluez, iwd, libell
- Fedora 41 update for bluez, iwd, libell
- Anolis OS update for wpa_supplicant
- SSID confusion in IEEE 802.11 standard in Arista Wireless Access Points