CVE-2023-52424 The advisory has been revoked - it doesn't affect any version of package wpa  (opens in a new tab)


Threat Intelligence

EPSS
0.72% (49th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2604-WPA-16223103
  • published24 Apr 2026
  • disclosed17 May 2024

Introduced: 17 May 2024

CVE-2023-52424  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:26.04.

NVD Description

Note: Versions mentioned in the description apply only to the upstream wpa package and not the wpa package as distributed by Ubuntu.

The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.