CVE Vulnerabilities

CVE-2024-20153

Missing Critical Step in Authentication

Published: Jan 06, 2025 | Modified: Jan 06, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.

Weakness

The product implements an authentication technique, but it skips a step that weakens the technique.

References