High severity7.5NVD Advisory· Published Apr 15, 2023· Updated Jun 17, 2026
CVE-2022-47522
CVE-2022-47522
Description
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
33- cpe:2.3:a:ieee:ieee_802.11:*:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:soho_250_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:soho_250w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sonicwave_224w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sonicwave_231c_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sonicwave_432o_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sonicwave_621_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sonicwave_641_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:sonicwave_681_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz270_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz270w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz300_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz300p_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz300w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz350_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz350w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz370_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz370w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz400_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz400w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz470_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz470w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz500_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz500w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz570_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz570p_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz570w_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz600_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz600p_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:sonicwall:tz670_firmware:-:*:*:*:*:*:*:*
- IEEE/IEEE 802.11 specificationsdescription
Patches
Vulnerability mechanics
References
4- papers.mathyvanhoef.com/usenix2023-wifi.pdfnvdExploitTechnical DescriptionThird Party Advisory
- psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0006nvdThird Party Advisory
- www.wi-fi.org/discover-wi-fi/passpointnvdNot Applicable
- www.freebsd.org/security/advisories/FreeBSD-SA-23:11.wifi.ascnvd
News mentions
0No linked articles in our index yet.