{"id":"CVE-2023-52160","details":"The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.","modified":"2026-09-11T03:31:03.608359676Z","published":"2024-02-22T00:00:00Z","related":["ALSA-2024:2517","SUSE-SU-2024:0764-1","SUSE-SU-2024:0764-2","SUSE-SU-2024:0818-1","SUSE-SU-2024:0819-1","SUSE-SU-2024:3354-1","SUSE-SU-2025:20089-1","openSUSE-SU-2024:13694-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52160.json"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N46C4DTVUWK336OYDA4LGALSC5VVPTCC/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QU6IR4KV3ZXJZLK2BY7HAHGZNCP7FPNI/"},{"type":"WEB","url":"https://w1.fi/cgit/hostap/commit/?id=8e6485a1bcb0baffdea9e55255a81270b768439c"},{"type":"WEB","url":"https://www.top10vpn.com/research/wifi-vulnerabilities/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52160.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N46C4DTVUWK336OYDA4LGALSC5VVPTCC/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QU6IR4KV3ZXJZLK2BY7HAHGZNCP7FPNI/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-52160"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/02/msg00013.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.w1.fi/cgit/hostap","events":[{"introduced":"0"},{"fixed":"cff80b4f7d3c0a47c052e8187d671710f48939e4"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0"},{"fixed":"2.10"}]}}],"versions":["hostap_2_9","hostap_2_8","hostap_2_7","hostap_2_6","hostap_2_5","hostap_2_4","hostap_2_3","hostap_2_2","hostap_2_1","aosp-kk-from-upstream","hostap_2_0","aosp-jb-start","hostap-1-bp","hostap_0_7_2","hostap_0_7_1","hostap_0_7_0","hostap_0_6_7","hostap_0_6_6","hostap_0_6_5","hostap_0_6_4","hostap_0_6_3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-52160.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}