CVE-2023-52424 Information
May 18, 2024
cve
Description
The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP Home WPA3 SAE-loop. Enterprise 802.1X/EAP Mesh AMPE or FILS aka an \SSID Confusion\ issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys and because there is not a protected exchange of an SSID during a 4-way handshake.
Reference
https://www.wi-fi.org/news-events/press-releases https://mentor.ieee.org/802.11/dcn/24/11-24-0938-03-000m-protect-ssid-in-4-way-handshake.docx https://www.top10vpn.com/research/wifi-vulnerability-ssid/ https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf
Share on: