The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade wpa_supplicant | May 13, 2024 | Feb 22, 2024 |
| Alpine Linux | — | Upgrade wpa_supplicant | Mar 26, 2024 | Feb 22, 2024 |
| Amazon Linux Ami 2 | — | Upgrade wpa_supplicantUpgrade wpa_supplicant-debuginfo | Mar 5, 2024 | Feb 22, 2024 |
| Debian | — | Upgrade wpa | Feb 29, 2024 | Feb 22, 2024 |
| Huawei Euleros 2_0_sp8 | — | Upgrade wpa_supplicant | Jul 23, 2024 | Feb 22, 2024 |
| Oracle_linux | — | Upgrade wpa_supplicant | May 9, 2024 | Feb 16, 2024 |
| Redhat_linux | — | Upgrade wpa_supplicant-debugsourceUpgrade wpa_supplicantUpgrade wpa_supplicant-debuginfoNo solution exists | May 1, 2024 | Feb 22, 2024 |
| Rocky_linux | — | Upgrade wpa_supplicant-debugsourceUpgrade wpa_supplicantUpgrade wpa_supplicant-debuginfo | May 13, 2024 | Feb 22, 2024 |
| Suse | — | Upgrade wpa_supplicant-guiUpgrade wpa_supplicant | Mar 6, 2024 | Feb 22, 2024 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 22, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub