MAC Address Spoofing Vulnerability in IEEE 802.11 Specifications
CVE-2022-47522
7.5HIGH
What is CVE-2022-47522?
The IEEE 802.11 specifications, including versions up to 802.11ax, are vulnerable to attacks wherein an adversary can spoof a target's MAC address to intercept target-destined frames. This can be achieved by sending specially crafted Power Save frames to the access point and subsequently transmitting other frames such as authentication or re-association frames. Notably, this vulnerability exists because the specifications do not mandate that an access point clears its transmit queue prior to the deletion of a client's pairwise encryption key, thereby allowing potential misuse and exposure of sensitive data.
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved