#VU86768 Improper authentication in wpa_supplicant - CVE-2023-52160
Published: February 23, 2024 / Updated: September 6, 2024
wpa_supplicant
Jouni Malinen
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the PEAP implementation. A remote attacker can bypass authentication process by sending an EAP-TLV Success packet instead of starting Phase 2.
Successful exploitation of the vulnerability requires that wpa_supplicant is configured to not verify the network's TLS certificate during Phase 1 authentication.