CVE-2022-47522: High severity ieee 802.11 vulnerability
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-47522?
CVE-2022-47522 is a vulnerability in the IEEE 802.11 specifications that allows physically proximate attackers to intercept target-destined frames.
How severe is CVE-2022-47522?
CVE-2022-47522 has a severity rating of 7.5, which is considered high.
Which software is affected by CVE-2022-47522?
The affected software includes IEEE 802.11 and Sonicwall TZ series firmware versions.
How can an attacker exploit CVE-2022-47522?
An attacker can exploit CVE-2022-47522 by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point.
Are Sonicwall TZ series devices vulnerable to CVE-2022-47522?
Yes, Sonicwall TZ series devices with vulnerable firmware versions are affected by CVE-2022-47522.