CVE-2015-5310

Description

The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or cause a denial of service (ignored packets) via a WNM Sleep Mode response.

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.304

Associated Vulnerability

VulnerabilityOS Platform
client support for WPA and WPA2 (USN-2808-1) hostapd_2.4-0ubuntu3.2_i386.debLinux
client support for WPA and WPA2 (USN-2808-1) hostapd_2.4-0ubuntu3.2_amd64.debLinux
client support for WPA and WPA2 (USN-2808-1) wpasupplicant_2.4-0ubuntu3.2_i386.debLinux
client support for WPA and WPA2 (USN-2808-1) wpasupplicant_2.4-0ubuntu3.2_amd64.debLinux
SUSE-SU-2016:2305-1(SUSE Linux Enterprise Desktop 12-SP1 ) wpa_supplicant-2.2-14.2.x86_64.rpmLinux
SUSE-SU-2016:2305-1(SUSE Linux Enterprise Desktop 12-SP1 ) wpa_supplicant-debuginfo-2.2-14.2.x86_64.rpmLinux
SUSE-SU-2016:2305-1(SUSE Linux Enterprise Desktop 12-SP1 ) wpa_supplicant-debugsource-2.2-14.2.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234