ZeroHour

CVE-2022-47522

PoC
CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
Description

The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.

Vendors
ieeesonicwall
Products
ieee 802.11, tz670 firmware, tz570 firmware, tz570p firmware, tz570w firmware, tz470 firmware, tz470w firmware, tz370 firmware, tz370w firmware, tz270 firmware, tz270w firmware, tz600 firmware
Weakness
CWE-290
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.