CVE-2011-5053
Summary
| CVE | CVE-2011-5053 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-01-06 20:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to discover the PIN value, and consequently discover the Wi-Fi network password or reconfigure an access point, by reading EAP-NACK messages. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wi-fi | Wifi Protected Setup Protocol | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Wi-Fi Protected Setup PIN Brute Force Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | |
| reaver-wps - Brute force attack against Wifi Protected Setup - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| Wi-Fi Protected Setup PIN brute force vulnerability « .braindump – RE and stuff | af854a3a-2127-422b-91ae-364da2661108 | sviehb.wordpress.com | |
| sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf | af854a3a-2127-422b-91ae-364da2661108 | sviehb.files.wordpress.com | |
| VU#723755 - WiFi Protected Setup (WPS) PIN brute force vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| US-CERT Technical Cyber Security Alert TA12-006A -- Wi-Fi Protected Setup (WPS) Vulnerable to Brute-Force Attack | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.