CVE-2022-37660
CVE-2022-37660
Título es
CVE-2022-37660
Mar, 11/02/2025 – 23:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2022-37660
Descripción en
In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future bootstrapping by passively observing public keys, re-using the encrypting element Qi and subtracting it from the captured message M (X = M – Qi). This will result in the public ephemeral key X; the only element required to subvert the PKEX association.
12/02/2025
12/02/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off