CVE-2023-52161 is a high-severity authentication bypass vulnerability affecting the Access Point functionality in iNet wireless daemon (IWD) versions prior to 2.14. An attacker can gain unauthorized access to a protected Wi-Fi network by manipulating the EAPOL handshake, specifically by sending an all-zero key in Msg4/4, bypassing the legitimate password. This vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector and low attack complexity, potentially leading to full confidentiality compromise. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.14CPE matchmatch criteria | cpe:2.3:a:intel:inet_wireless_daemon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.