News by sead on 2005-11-16
New release: UWlwapp, LWAPP AP Denial of Service - POC. The Light Weight Access Point Protocol (LWAPP) is designed to make communications between access points and wireless switches automatic. The Privacy and Authentication of control messages are provided by applying AES-CCM on the messages with random session keys. On all messages ? Well, not entirely... A denial-of-service vulnerability exists within the processing of DISCOVERY_REQUESTS (non encrypted) by the WLAN controller.