HomeDefectsLIN1024-408
Fixed

LIN1024-408 : Security Advisory - wpa-supplicant - CVE-2023-52160

Created: Apr 29, 2024    Updated: Oct 28, 2024
Resolved Date: Oct 27, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.3
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.

https://nvd.nist.gov/vuln/detail/CVE-2023-52160

CVEs