Security News New Wi-Fi Vulnerability Enables Network Eavesdropping via Downgrade Attacks

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,333
Researchers have discovered a new security vulnerability stemming from a design flaw in the IEEE 802.11 Wi-Fi standard that tricks victims into connecting to a less secure wireless network and eavesdrop on their network traffic.

The SSID Confusion attack, tracked as CVE-2023-52424, impacts all operating systems and Wi-Fi clients, including home and mesh networks that are based on WEP, WPA3, 802.11X/EAP, and AMPE protocols.

The method "involves downgrading victims to a less secure network by spoofing a trusted network name (SSID) so they can intercept their traffic or carry out further attacks," Top10VPN said, which collaborated with KU Leuven professor and researcher Mathy Vanhoef.

"A successful SSID Confusion attack also causes any VPN with the functionality to auto-disable on trusted networks to turn itself off, leaving the victim's traffic exposed."
 

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,759
I am not sure to what extent this is a problem nowadays, given that HTTP is almost fully phased out. Definitely a security risk though.
 
F

ForgottenSeer 109138

I am not sure to what extent this is a problem nowadays, given that HTTP is almost fully phased out. Definitely a security risk though.
There is not only this, but its a lot of work considering the attacker must be within range to perform an AiTM, for a targeted attack, this scenario has the risk-adjusted return factor of minimal and not likely something that would be deployed often if ever.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top