Skip to main content

WPA2 Key Decryption Vulnerability

Xbash is a newly observed worm targeting exposed servers worldwide. Written in Python using code taken from the NotPetya malware.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Xbash is a newly observed worm targeting exposed servers worldwide. Written in Python using code taken from the NotPetya malware.

Threat details

The vulnerability lies in how the wpa_supplicant program, used to configure Wi-Fi on devices, processes Extensible Authentication Protocol over LAN (EAPOL) keys. An attacker could modify this process to force wpa_supplicant to decrypt the EAPOL-key data fields without first authenticating them. This may allow them to recover the encryption keys, at which point they would be able to intercept all data sent between the access point and the device.

However, full recovery of an encryption key is estimated to take over 20 minutes, provided the access point does not change the keys during this time. The researchers also note that WPA2 is only vulnerable if used with the Temporal Key Integrity Protocol (TKIP) encryption. TKIP was deprecated in 2012 by the more secure Counter Mode CBC-MAC Protocol (CCMP).

For further information


Remediation steps

Type Step
The wpa_supplicant maintainers have issued a hotfix to address this vulnerability. Users and administrators are encouraged to review this fix and apply the update immediately.

Last edited: 17 February 2020 12:58 pm