HomeSecurityWiFi protocol flaw allows network traffic to be compromised

WiFi protocol flaw allows network traffic to be intercepted

Cybersecurity experts have disclosed a critical security vulnerability in the IEEE 802.11 WiFi protocol, which allows hackers to manipulate access points to reveal network frames as plain text.

WiFi protocol flaw allows network traffic to be intercepted

WiFi frames are data packets that serve as a means of communication between two endpoints and consist of a header, data payload, and a trailer. These containers contain critical details such as the source MAC address, the destination MAC address, control information, and management information.

To ensure effective data exchange, these frames are transmitted in a controlled manner and organized into queues. Additionally, the states of busy/idle reception points are monitored to avoid collisions and achieve maximum performance.

Researchers discovered that queued/buffered frames are not adequately protected from adversaries, who can manipulate data transmission, client spoofing, frame redirection, and reception.

Power-saving flaw

To save power, the IEEE 802.11 standard has power saving that allow WiFi devices to cache or queue frames intended for sleeping devices.

When a client station enters sleep mode, it transmits a frame to the access point containing an explicit power‑saving bit. Then all frames destined for this client device are queued by the access point until the wake‑up state is achieved.

However, the standard does not provide specific guidance on ensuring these frames are queued and does not set limits, such as how long the frames can remain in this state.

After the client station is activated, the access point takes the frames from its queue, encrypts them, and sends them to their final destination.

An attacker can impersonate the MAC address of a device on the network and send power-saving frames to access points, causing them to store data addressed to that target. They then transmit a wake-up frame to obtain all of that stored information.

The data transmitted over the WiFi network is generally secured either by an encryption key with a group address, which is shared by all devices in the system, or by a reliable bidirectional communication that allows encrypting frames with an exclusive encryption key per pair for each device.

To manipulate the security of the frames, an attacker can send authentication and connection frames to the access point. This process forces the transmission of plain text or encryption with the attacker's own key.

This attack is possible using custom tools created by the researchers called MacStealer , which can test WiFi networks for client isolation bypasses and intercept traffic intended for other clients at the MAC level .

According to researchers, many network device models from various manufacturers, including Lancom, Aruba, Cisco, Asus and D-Link, are vulnerable to these attacks.

WiFi

Cisco acknowledges the flaw

Cisco was the first company to respond to the risk posed by this WiFi protocol vulnerability, acknowledging that it could be exploited in its Wireless Access Point and Meraki products with wireless capabilities.

Despite this, Cisco confidently stated that the recovered frames are unlikely to threaten the overall security of a network protected with appropriate measures.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS