Name
CVE-2023-52160
Description
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.
Published Date
Updated Date
Workaround
-
Advisories
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QU6IR4KV3ZXJZLK2BY7HAHGZNCP7FPNI/Third Party Advisory
https://www.top10vpn.com/research/wifi-vulnerabilities/Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QU6IR4KV3ZXJZLK2BY7HAHGZNCP7FPNI/Third Party Advisory
https://www.top10vpn.com/research/wifi-vulnerabilities/Third Party Advisory
Analysis#
Vulnerability Ratings#
6.5
CVSSv31
6.5
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11
Not Affected
buildroot
2025.02.x
2.11
Not Affected
buildroot
master
2.11
Not Affected
buildroot
master
2.11
Not Affected
openwrt
master
2026.04.02~b004de0bf1b54d669d358b7f33d6f474bd9719a6-r1
Not Affected
openwrt
master
2020.06.08~5a8b366233f5585e68a4ffbb604fbb4a848eb325-r10
Not Affected
openwrt
openwrt-25.12
2025.08.26~ca266cc24d8705eb1a2a0857ad326e48b1408b20-r1
Not Affected
openwrt
openwrt-25.12
2020.06.08~5a8b366233f5585e68a4ffbb604fbb4a848eb325-r10
Not Affected
yocto
kirkstone
2.10
Patched
yocto
kirkstone
2.10
Patched
yocto
master
2.11
Not Affected
yocto
master
2.11
Not Affected
Resolved with patches#
hostapd (yocto:kirkstone)
#
Title
Author
Resolve
1
PEAP client: Update Phase 2 authentication requirements
Jouni Malinen <j@w1.fi>
CVE-2023-52160
wpa-supplicant (yocto:kirkstone)
#
Title
Author
Resolve
1
PEAP client: Update Phase 2 authentication requirements
Jouni Malinen <j@w1.fi>
CVE-2023-52160
hostapd (yocto:scarthgap)
#
Title
Author
Resolve
1
PEAP client: Update Phase 2 authentication requirements
Jouni Malinen <j@w1.fi>
CVE-2023-52160
wpa-supplicant (yocto:scarthgap)
#
Title
Author
Resolve
1
PEAP client: Update Phase 2 authentication requirements
Jouni Malinen <j@w1.fi>
CVE-2023-52160