Debian Iwd vulnerabilities
4 known vulnerabilities affecting debian/iwd.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-52161P3HIGHCVSS 7.5fixed in iwd 2.3-1+deb12u1 (bookworm)2023
CVE-2023-52161 [HIGH] CVE-2023-52161: iwd - The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wirel...
The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key.
Scope: local
bookworm: resolved (fixed in 2.3-1+deb12u1)
bullseye: resolved
debian
CVE-2020-17497P3HIGHCVSS 8.1fixed in iwd 1.9-1 (bookworm)2020
CVE-2020-17497 [HIGH] CVE-2020-17497: iwd - eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a ...
eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4.
Scope: local
bookworm: resolved (fixed in 1.9-1)
bullseye: resolved (fixed in 1.9-1)
forky: resolved (fixed in 1.9-1)
sid: resolved (fixed in 1.9-1)
trixie: resolved (fixed in 1.9-1)
debian
CVE-2024-28084P4HIGHCVSS 7.5fixed in iwd 2.16-1 (forky)2024
CVE-2024-28084 [HIGH] CVE-2024-28084: iwd - p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a...
p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.16-1)
sid: resolved (fixed in 2.16-1)
trixi
debian
CVE-2020-8689P4MEDIUMCVSS 6.5fixed in iwd 1.5-1 (bookworm)2020
CVE-2020-8689 [MEDIUM] CVE-2020-8689: iwd - Improper buffer restrictions in the Intel(R) Wireless for Open Source before ver...
Improper buffer restrictions in the Intel(R) Wireless for Open Source before version 1.5 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Scope: local
bookworm: resolved (fixed in 1.5-1)
bullseye: resolved (fixed in 1.5-1)
forky: resolved (fixed in 1.5-1)
sid: resolved (fixed in 1.5-1)
trixie: resolved (fixed in 1.5-1)
debian