Impact
An omission in driver‑based PMKSA to skip validating the network context and AKMP matching for PMKSA caching. A local attacker can exploit this flaw to manipulate the PMK session active without proper authorization, thereby compromising the ability to authenticate against wireless networks.
Affected Systems
All releases of wpa_supplicant before version 2.12 are affected. Based on the description, it is inferred that the vulnerability is present regardless of the operating system, because the defect lies in the core wpa_supplicant code that interacts with any driver supporting PMKSA caching.
Risk and Exploitability
The CVSS score is 7.1. The EPSS score indicates a low probability of exploitation. The flaw is not listed in CISA's KEV catalog, indicating no publicly known exploit kits. The vulnerability allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching, so the attack vector is local. The attacker would need control over the driver to influence PMKSA handling. If exploited, the attacker could gain unauthorized network access.
OpenCVE Enrichment