CVE-2022-47522
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- ieee/ieee 802.11 · sonicwall/tz670 firmware · sonicwall/tz570 firmware · sonicwall/tz570p firmware · sonicwall/tz570w firmware · sonicwall/tz470 firmware · sonicwall/tz470w firmware · sonicwall/tz370 firmware · sonicwall/tz370w firmware · sonicwall/tz270 firmware · sonicwall/tz270w firmware · sonicwall/tz600 firmware · sonicwall/tz600p firmware · sonicwall/tz500 firmware · sonicwall/tz500w firmware · sonicwall/tz400 firmware · sonicwall/tz400w firmware · sonicwall/tz350 firmware · sonicwall/tz350w firmware · sonicwall/tz300 firmware · +10 more
- Source
- cve@mitre.org
References
- https://papers.mathyvanhoef.com/usenix2023-wifi.pdfExploit, Technical Description, Third Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0006Third Party Advisory
- https://www.freebsd.org/security/advisories/FreeBSD-SA-23:11.wifi.asc
- https://www.wi-fi.org/discover-wi-fi/passpointNot Applicable
- https://papers.mathyvanhoef.com/usenix2023-wifi.pdfExploit, Technical Description, Third Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0006Third Party Advisory
- https://www.freebsd.org/security/advisories/FreeBSD-SA-23:11.wifi.asc
- https://www.wi-fi.org/discover-wi-fi/passpointNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.