How is your Wi-Fi connection today? DoS attacks on WPA3-SAE
This work offers a full-fledged empirical study on Denial of Service (DoS) against SAE. By utilizing both real-life modern Wi-Fi 6 certified and non-certified equipment and the OpenBSD's hostapd, we expose a significant number of novel DoS assaults affecting virtually any access point. No less important, more than a dozen of vendor-depended and severe zero-day DoS assaults are manifested, showing that the implementation of the protocol by vendors is not yet mature enough. The fallout of the introduced attacks to the associated stations ranges from a temporary loss of Internet connectivity to outright disconnection. To our knowledge, this work provides the first wholemeal appraisal of SAE's mechanism endurance against DoS. The following repository contains some exploits of the identified attacks. link: easy-exploits
Award
The research paper published in the international Journal of Information Security and Applications (JISA), Elsevier has received the Dr KW Wong Annual Best Paper Award for 2022. The announcement can be found at JISA awards page.
Testbed
As shown in the below table, all the utilized devices were WPA3-capable, with almost half of them being WPA3 certified. In almost all the cases, every tested AP operated on channel 36 (5 GHz) with a 802.11ax configuration and a WPA3-Personal setup. Three STAs were used; the first was a desktop machine equipped with a Gigabyte GCWBAX200 (Intel AX200) wireless network interface controller (WNIC) operating on Windows 10, the second was a laptop machine on Ubuntu v20.04 with an Intel AX200 WNIC, and the third was a Samsung S20 FE smartphone on Android 11. All STAs obtained their last OS update on the 20th of March 2021.
Generic attacks
We expose seven diverse ways of potentially leading the connected STAs into a state of denial of Internet access or simply disconnecting them from the AP. It is important to note that all the generic attacks have been performed with just one attack terminal (instance) on a single WNIC, and therefore their magnitude is expected to be much more intensive under a multi instance or DDoS orchestration. The table below summarizes whether each attack was efficacious against every examined AP; note that the consequence of an assault was equivalent across every STA, either MS Windows, Linux, or Android.
Chipset-vendor dependent attacks
As summarized in the following table, our work also exposes a significant number of zero-day DoS attacks affecting either Broadcom, Qualcomm or MediaTek based APs. Specifically, mainly through fuzz testing, we discovered 13 different ways of mounting an easy to implement DoS attack that can straightforwardly disconnect an STA or render it incapable of receiving Internet services. The assaults make use of specially crafted authentication frames. No less important, all the attacks were drastic in both the 2.4 GHz and 5 GHz frequency bands, and impacted all three STA devices, in pretty much the same way.
CVE IDs
The following list contains every CVE ID been assigned so far due to our research. It is to be noted that CVE IDs from the same chipset vendor refer and address the same issue(s).
Broadcom-based products. Patches for Doppelganger and attacks 1 to 7.
CVE-2021-37910 refers to ASUS products. Below is a list of the so far patched models.
- ROG Rapture GT-AX11000 from v3.0.0.4.386.44266
- ROG Rapture GT-AXE11000 from v3.0.0.4.386.45850
- ROG Rapture GT-AX11000 Call of Duty Black Ops 4 from v3.0.0.4.386.44266
- RT-AX3000 from v3.0.0.4.386.45674
- RT-AX55 from v3.0.0.4.386.45375
- RT-AX56U from v3.0.0.4.386.45898
- RT-AX56U_V2 from v3.0.0.4.386.45375
- RT-AX58U from v3.0.0.4.386.45674
- RT-AX68U from v3.0.0.4.386.45911
- RT-AX82U from v3.0.0.4.386.45375
- RT-AX82U GUNDAM EDITION from v3.0.0.4.386.45375
- RT-AX86 Series (RT-AX86U/RT-AX86S) from v3.0.0.4.386.45375
- RT-AX86U ZAKU II EDITION from v3.0.0.4.386.45375
- RT-AX88U from v3.0.0.4.386.44266
- RT-AX92U from v3.0.0.4.386.45898
- DSL-AX82U from v3.0.0.4.386.45660
- TUF Gaming AX5400 (TUF-AX5400) from v3.0.0.4.386.45407
- ASUS ZenWiFi XD6 from v3.0.0.4.386.45674
- ASUS ZenWiFi AX (XT8) from v3.0.0.4.386.45898
- TUF Gaming AX3000 from v3.0.0.4.386.45898
CVE-2021-41753 refers to D-Link products.
- DIR-X1560 from v1.04B04
- DIR-X6060 from v1.11B04
CVE-2021-40288 refers to TP-Link product(s).
- AX10v1 from V1_211014
MediaTek chipset solutions patched for 11 to 13 attacks
CVE-2021-41788 refers to MediaTek products.
Acknowledgments
We would like to thank TWCERT/CC for their assistance into communicating with each affected vendor under their scope.