MAC Address Spoofing Vulnerability in IEEE 802.11 Specifications
CVE-2022-47522

7.5HIGH

Key Information:

Vendor

Ieee

Vendor
CVE Published:
15 April 2023

What is CVE-2022-47522?

The IEEE 802.11 specifications, including versions up to 802.11ax, are vulnerable to attacks wherein an adversary can spoof a target's MAC address to intercept target-destined frames. This can be achieved by sending specially crafted Power Save frames to the access point and subsequently transmitting other frames such as authentication or re-association frames. Notably, this vulnerability exists because the specifications do not mandate that an access point clears its transmit queue prior to the deletion of a client's pairwise encryption key, thereby allowing potential misuse and exposure of sensitive data.

References

EPSS Score

14% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.