CVE-2023-52424 (SSID Confusion Attack)

CVSS v3.1 7.4 (High)
74% Progress
Advisories 1
NVD Status Awaiting Analysis

The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.

Weaknesses
CWE-304
Missing Critical Step in Authentication
Alias
CVE Status
PUBLISHED
NVD Status
Awaiting Analysis
CNA
MITRE
Published Date
2024-05-17 21:15:07
(3 months ago)
Updated Date
2024-08-29 20:35:48
(9 days ago)
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...