hostapd nieprawidłowo przetwarza spreparowane pakiety RADIUS. Gdy hostapd uwierzytelnia urządzenia Wi-Fi przy użyciu RADIUS, atakujący znajdujący się między hostapd a serwerem RADIUS może wstrzyknąć spreparowane pakiety RADIUS i zmusić uwierzytelnianie RADIUS do niepowodzenia.
▸ Pokaż oryginał (EN)
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LW1.fi Hostapd
APPW1.Fi≤ 2.11
Powiązane podatności
Side-channel attack w EAP-pwd w hostapd i wpa_supplicant (przed 2.10)
Atak side-channel na implementację SAE w hostapd i wpa_supplicant
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subs...
hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any...
The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar an...