Menu

Database

802.11 Lacks Authentication of Management Frames

WVE ID: WVE-2005-0019

Type: Vulnerability

Status: Candidate

Classification:
Authentication Management
Design Flaw

Description:
The 802.11 standard does not authenticate management frames. This exposes wireless devices to spoofing attacks.

Discussion:
The 802.11 standard defines three types of frames each having several sub-types. Management frames are one of these types and are used for discovering wireless networks, associating stations with a network and breaking these associations.

Because these frames are not authenticated, an attacker can impersonate another device and send spoofed management frames that target either a specific station or an entire wireless network. An effective client DoS technique involves impersonating an access point by sending Deauthentication frames with that AP's BSSID to a single client or the broadcast address (all clients) to knock them off the wireless network.

Similarly an attacker can flood an access point with spoofed Association Requests and possibly overflow its association table causing the AP to stop responding.

Credits

References
URL: http://standards.ieee.org/getieee802/download/802.11-1999.pdf
WVE: WVE-2005-0045
WVE: WVE-2005-0046
WVE: WVE-2005-0047
WVE: WVE-2005-0048

Released: 2000-01-01

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Mon Oct 24 17:33:12 -0700 2005

Candidate Date: Mon Oct 24 17:33:33 -0700 2005


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...