Site icon Auspreneur

Minister opposes bank reimbursement for ‘blanket’ scam

Academic researchers have discovered a vulnerability in the widely used 802.11 protocol, which enables an attacker to bypass encryption for certain types of traffic. Termed a protocol bug, the problem impacts multiple Wi-Fi implementations.

The vulnerability arises because of the absence of explicit guidance regarding the security contexts of buffered frames in the 802.11 standards, and the unprotected nature of the power-save bit in a frame’s header.

The researchers say this allows adversaries to force frames queued for a specific client, leading to disconnection and a denial-of-service attack.

The vulnerability affects a variety of networks, including enterprise networks using client isolation or ARP inspection, public hotspots using the Passpoint login mechanism, and home networks using WPA2 or WPA3 with client isolation enabled.

The paper states that Cisco was the first vendor to acknowledge the issue, and its policy enforcement via its Identity Services Engine can mitigate the attacks, while users should implement transport layer security to encrypt data traversing the network.

Exit mobile version