The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to discover the PIN value, and consequently discover the Wi-Fi network password or reconfigure an access point, by reading EAP-NACK messages.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2012-01-06T20:00:00
Updated: 2024-08-07T00:23:39.735Z
Reserved: 2012-01-06T00:00:00
Link: CVE-2011-5053
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-01-06T20:55:01.233
Modified: 2024-11-21T01:33:30.960
Link: CVE-2011-5053
Redhat
No data.