Improper authentication in wpa_supplicant - CVE-2023-52160

 

Improper authentication in wpa_supplicant - CVE-2023-52160

Published: February 23, 2024 / Updated: September 6, 2024


Vulnerability identifier: #VU86768
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-52160
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the PEAP implementation. A remote attacker can bypass authentication process by sending an EAP-TLV Success packet instead of starting Phase 2.

Successful exploitation of the vulnerability requires that wpa_supplicant is configured to not verify the network's TLS certificate during Phase 1 authentication.


Affected software

wpa_supplicant
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Brocade Fabric OS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Fedora
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
ESP-IDF
HPE SANnav Management Software
wpa_supplicant-debugsource
wpa_supplicant-debuginfo
wpa_supplicant
wpa_supplicant (Red Hat package)
wpa_supplicant-gui-debuginfo
wpa_supplicant-gui

How to mitigate CVE-2023-52160

Install updates from vendor's website.

SmartFabric Storage Software - update to 1.4.3
ESP-IDF - update to 5.3
LANTIME Operating System Firmware (LTOS) - update to 7.08.018
Brocade Fabric OS - addressed in versions 9.2.0c, 9.2.1a1, 9.2.2
HPE SANnav Management Software - update to 2.3.0a
wpa_supplicant-debugsource - addressed in versions 2.9-23.20.1, 2.9-150000.4.39.1, 2.10-150500.3.3.1, 2.10-150600.7.3.1
wpa_supplicant-debuginfo - addressed in versions 2.9-23.20.1, 2.9-150000.4.39.1, 2.10-150500.3.3.1, 2.10-150600.7.3.1
wpa_supplicant - addressed in versions 2.9-23.20.1, 2.9-150000.4.39.1, 2.10-150500.3.3.1, 2.10-150600.7.3.1
wpa_supplicant - update to 2.10-2
wpa_supplicant (Red Hat package) - update to 2.10-5.el9
wpa_supplicant - addressed in versions 2.10-7.fc38, 2.10-9.fc39
wpa_supplicant-gui-debuginfo - addressed in versions 2.10-150500.3.3.1, 2.10-150600.7.3.1
wpa_supplicant-gui - addressed in versions 2.10-150500.3.3.1, 2.10-150600.7.3.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins