Improper authentication in wpa_supplicant - CVE-2023-52160
Published: February 23, 2024 / Updated: September 6, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the PEAP implementation. A remote attacker can bypass authentication process by sending an EAP-TLV Success packet instead of starting Phase 2.
Successful exploitation of the vulnerability requires that wpa_supplicant is configured to not verify the network's TLS certificate during Phase 1 authentication.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Brocade Fabric OS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
Fedora
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
ESP-IDF
HPE SANnav Management Software
wpa_supplicant-debugsource
wpa_supplicant-debuginfo
wpa_supplicant
wpa_supplicant (Red Hat package)
wpa_supplicant-gui-debuginfo
wpa_supplicant-gui
How to mitigate CVE-2023-52160
ESP-IDF - update to 5.3
LANTIME Operating System Firmware (LTOS) - update to 7.08.018
Brocade Fabric OS - addressed in versions 9.2.0c, 9.2.1a1, 9.2.2
HPE SANnav Management Software - update to 2.3.0a
wpa_supplicant-debugsource - addressed in versions 2.9-23.20.1, 2.9-150000.4.39.1, 2.10-150500.3.3.1, 2.10-150600.7.3.1
wpa_supplicant-debuginfo - addressed in versions 2.9-23.20.1, 2.9-150000.4.39.1, 2.10-150500.3.3.1, 2.10-150600.7.3.1
wpa_supplicant - addressed in versions 2.9-23.20.1, 2.9-150000.4.39.1, 2.10-150500.3.3.1, 2.10-150600.7.3.1
wpa_supplicant - update to 2.10-2
wpa_supplicant (Red Hat package) - update to 2.10-5.el9
wpa_supplicant - addressed in versions 2.10-7.fc38, 2.10-9.fc39
wpa_supplicant-gui-debuginfo - addressed in versions 2.10-150500.3.3.1, 2.10-150600.7.3.1
wpa_supplicant-gui - addressed in versions 2.10-150500.3.3.1, 2.10-150600.7.3.1
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Authentication bypass in wpa_supplicant
- Fedora 38 update for wpa_supplicant
- Fedora 39 update for wpa_supplicant
- SUSE update for wpa_supplicant
- SUSE update for wpa_supplicant
- SUSE update for wpa_supplicant
- Red Hat Enterprise Linux 9 update for wpa_supplicant
- Multiple vulnerabilities in esp-idf
- SUSE update for wpa_supplicant
- HPE SANnav Management Software update for wpa_supplicant
- Multiple vulnerabilities in Brocade Fabric OS
- Anolis OS update for wpa_supplicant
- Dell SmartFabric Storage Software update for third-party components
- Meinberg LANTIME firmware update for third-party components (December 2024)