The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-wpa_supplicant | May 13, 2024 | Feb 22, 2024 | |
| Alpine Linux | alpine-linux-upgrade-wpa_supplicant | Mar 26, 2024 | Feb 22, 2024 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-wpa_supplicantamazon-linux-ami-2-upgrade-wpa_supplicant-debuginfo | Mar 5, 2024 | Feb 22, 2024 | |
| Debian | debian-upgrade-wpa | Feb 29, 2024 | Feb 22, 2024 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-wpa_supplicant | Jul 23, 2024 | Feb 22, 2024 | |
| Oracle_linux | — | oracle-linux-upgrade-wpa-supplicant | May 9, 2024 | Feb 16, 2024 |
| Redhat_linux | redhat-upgrade-wpa_supplicantredhat-upgrade-wpa_supplicant-debuginforedhat-upgrade-wpa_supplicant-debugsource | May 1, 2024 | Feb 22, 2024 | |
| Rocky_linux | rocky-upgrade-wpa_supplicantrocky-upgrade-wpa_supplicant-debuginforocky-upgrade-wpa_supplicant-debugsource | May 13, 2024 | Feb 22, 2024 | |
| Suse | — | suse-upgrade-wpa_supplicantsuse-upgrade-wpa_supplicant-gui | Mar 6, 2024 | Feb 22, 2024 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Feb 22, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub