#VU86770 Improper Authentication in iNet wireless daemon (IWD) - CVE-2023-52161
Published: February 23, 2024
iNet wireless daemon (IWD)
iwd.wiki.kernel.org
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error within the eapol_auth_key_handle() function in eapol.c. A remote attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key and gain unauthorized access to the network.