05-29-2024 12:56 PM
Hi,
I would like to know if Meraki has some taken any steps to mitigate this vulnerability.
We are:
- using WPA2 encryption and not WPA3
- using RADIUS authentication
I hope Meraki will release a patch to mitigate the vulnerability. Does anyone know or shed some light on the steps that Meraki is going to take or is advising the customers ?
05-29-2024 12:58 PM
What vulnerability? Do you have the CVE?
05-29-2024 01:00 PM
05-29-2024 01:06 PM
This CVE is from 2023, Meraki has probably already released the fix some time ago, as they frequently release new updates.
Have you already contacted support?
05-29-2024 01:13 PM
Doubt that Meraki has published a fix for that. The CVE was published this month.
05-29-2024 02:10 PM
Without knowing exactly what the underlying mechanisms is in this specific CVE, from what I'm reading about it, it's simply an overall design flaw in the 802.11 standard.
It's always been there, and will always be there.
Basically it aims at tricking a user to associate to your malicious and less secure SSID (a honeypot) and eavesdrop on all your traffic.
If you really want to mitigate it, there's an easy fix.
Turn of all your WiFi and Access Points, and cable your devices to the network.
05-29-2024 04:30 PM
It's a day old I doubt any vendor has patched it as it's still being analysed.
05-29-2024 05:47 PM
There is no public bug or PSIRT for this vulnerability yet, given it's still pretty fresh.
Raise a support ticket for more information as they may already be investigating internally.
05-29-2024 05:58 PM
NOTE: I DO NOT KNOW, THE FULL INS AND OUTS OF THIS VULNERABILITY.
That said, Meraki Air Marshal does have some level of mitigation from Rouge SSIDs. See below guide for further details.
https://documentation.meraki.com/MR/Monitoring_and_Reporting/Air_Marshal
05-29-2024 08:20 PM
Original writeup came out a few weeks ago: https://www.top10vpn.com/research/wifi-vulnerability-ssid/
I wouldn't expect a fix to be released quickly, if at all!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide