CVE-2011-5053
Last modified
CVE-2011-5053 is a vulnerability of currently unknown severity. The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to discover the PIN value, and consequently discover the Wi-Fi network password or reconfigure an access point, by reading EAP-NACK messages.. EPSS estimates a 3.34% chance of exploitation in the next 30 days.
Description
The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to discover the PIN value, and consequently discover the Wi-Fi network password or reconfigure an access point, by reading EAP-NACK messages.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wi-Fi | Wifi Protected Setup Protocol | All versions |
References
- http://www.kb.cert.org/vuls/id/723755US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA12-006A.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/723755US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA12-006A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-5053?
How severe is CVE-2011-5053?
How do I fix CVE-2011-5053?
Are you affected by CVE-2011-5053?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
