Description
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.
Published: 2023-04-15
Score: 7.5 High
EPSS: 17.6% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Ieee Ieee 802.11
Sonicwall Soho 250 Soho 250 Firmware Soho 250w Soho 250w Firmware Sonicwave 224w Sonicwave 224w Firmware Sonicwave 231c Sonicwave 231c Firmware Sonicwave 432o Sonicwave 432o Firmware Sonicwave 621 Sonicwave 621 Firmware Sonicwave 641 Sonicwave 641 Firmware Sonicwave 681 Sonicwave 681 Firmware Tz270 Tz270 Firmware Tz270w Tz270w Firmware Tz300 Tz300 Firmware Tz300p Tz300p Firmware Tz300w Tz300w Firmware Tz350 Tz350 Firmware Tz350w Tz350w Firmware Tz370 Tz370 Firmware Tz370w Tz370w Firmware Tz400 Tz400 Firmware Tz400w Tz400w Firmware Tz470 Tz470 Firmware Tz470w Tz470w Firmware Tz500 Tz500 Firmware Tz500w Tz500w Firmware Tz570 Tz570 Firmware Tz570p Tz570p Firmware Tz570w Tz570w Firmware Tz600 Tz600 Firmware Tz600p Tz600p Firmware Tz670 Tz670 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-06T15:54:53.804Z

Reserved: 2022-12-18T00:00:00.000Z

Link: CVE-2022-47522

cve-icon Vulnrichment

Updated: 2024-08-03T14:55:08.299Z

cve-icon NVD

Status : Modified

Published: 2023-04-15T02:15:07.290

Modified: 2025-02-06T16:15:31.443

Link: CVE-2022-47522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses