#VU59106 Input validation error in wpa_supplicant - CVE-2021-30004
Published: December 29, 2021 / Updated: January 17, 2022
wpa_supplicant
Jouni Malinen
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to insufficient validation of user-supplied input in tls/pkcs1.c and tls/x509v3.c files in wpa_supplicant and hostapd when handling AlgorithmIdentifier parameters. A remote attacker can pass specially crafted input to the application and perform MitM attack.