Improper Authentication in iNet wireless daemon (IWD) - CVE-2023-52161
Published: February 23, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error within the eapol_auth_key_handle() function in eapol.c. A remote attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key and gain unauthorized access to the network.
Affected software
Debian Linux
Fedora
libell
iwd (Debian package)
iwd
How to mitigate CVE-2023-52161
libell - addressed in versions 0.63-1.fc38, 0.63-1.fc39, 0.63-1.fc40
iwd (Debian package) - addressed in versions 1.14-3+deb11u1, 2.3-1+deb12u1
iwd - addressed in versions 2.15-1.fc38, 2.15-1.fc39, 2.15-1.fc40, 2.16-1.fc39, 2.16-1.fc40