MAC Address Spoofing Vulnerability in IEEE 802.11 Specifications
CVE-2022-47522
7.5HIGH
What is CVE-2022-47522?
The IEEE 802.11 specifications, including versions up to 802.11ax, are vulnerable to attacks wherein an adversary can spoof a target's MAC address to intercept target-destined frames. This can be achieved by sending specially crafted Power Save frames to the access point and subsequently transmitting other frames such as authentication or re-association frames. Notably, this vulnerability exists because the specifications do not mandate that an access point clears its transmit queue prior to the deletion of a client's pairwise encryption key, thereby allowing potential misuse and exposure of sensitive data.
