EAP Vulnerability in Espressif Products Allows Zero PMK Installation
CVE-2019-12587
8.1HIGH
What is CVE-2019-12587?
The EAP peer implementation in the affected Espressif products allows the installation of a zero Pairwise Master Key (PMK) following the completion of any EAP authentication method. This vulnerability permits attackers within radio range to exploit the system through replay attacks, frame decryption, or spoofing, particularly via the use of a rogue access point. Safeguarding against this risk calls for timely updates and security best practices in wireless networks.