DoS attacks on WPA3-SAE

Dec 08, 2021

How is your Wi-Fi connection today? DoS attacks on WPA3-SAE

This work offers a full-fledged empirical study on Denial of Service (DoS) against SAE. By utilizing both real-life modern Wi-Fi 6 certified and non-certified equipment and the OpenBSD's hostapd, we expose a significant number of novel DoS assaults affecting virtually any access point. No less important, more than a dozen of vendor-depended and severe zero-day DoS assaults are manifested, showing that the implementation of the protocol by vendors is not yet mature enough. The fallout of the introduced attacks to the associated stations ranges from a temporary loss of Internet connectivity to outright disconnection. To our knowledge, this work provides the first wholemeal appraisal of SAE's mechanism endurance against DoS. The following repository contains some exploits of the identified attacks. link: easy-exploits

Award

The research paper published in the international Journal of Information Security and Applications (JISA), Elsevier has received the Dr KW Wong Annual Best Paper Award for 2022. The announcement can be found at JISA awards page.

Testbed

As shown in the below table, all the utilized devices were WPA3-capable, with almost half of them being WPA3 certified. In almost all the cases, every tested AP operated on channel 36 (5 GHz) with a 802.11ax configuration and a WPA3-Personal setup. Three STAs were used; the first was a desktop machine equipped with a Gigabyte GCWBAX200 (Intel AX200) wireless network interface controller (WNIC) operating on Windows 10, the second was a laptop machine on Ubuntu v20.04 with an Intel AX200 WNIC, and the third was a Samsung S20 FE smartphone on Android 11. All STAs obtained their last OS update on the 20th of March 2021.

DoS WPA3 testbed devices

Generic attacks

We expose seven diverse ways of potentially leading the connected STAs into a state of denial of Internet access or simply disconnecting them from the AP. It is important to note that all the generic attacks have been performed with just one attack terminal (instance) on a single WNIC, and therefore their magnitude is expected to be much more intensive under a multi instance or DDoS orchestration. The table below summarizes whether each attack was efficacious against every examined AP; note that the consequence of an assault was equivalent across every STA, either MS Windows, Linux, or Android.

Generic DoS attacks on WPA3

Chipset-vendor dependent attacks

As summarized in the following table, our work also exposes a significant number of zero-day DoS attacks affecting either Broadcom, Qualcomm or MediaTek based APs. Specifically, mainly through fuzz testing, we discovered 13 different ways of mounting an easy to implement DoS attack that can straightforwardly disconnect an STA or render it incapable of receiving Internet services. The assaults make use of specially crafted authentication frames. No less important, all the attacks were drastic in both the 2.4 GHz and 5 GHz frequency bands, and impacted all three STA devices, in pretty much the same way.

Vendor-dependent DoS attacks

CVE IDs

The following list contains every CVE ID been assigned so far due to our research. It is to be noted that CVE IDs from the same chipset vendor refer and address the same issue(s).

Broadcom-based products. Patches for Doppelganger and attacks 1 to 7.

CVE-2021-37910 refers to ASUS products. Below is a list of the so far patched models.

  • ROG Rapture GT-AX11000 from v3.0.0.4.386.44266
  • ROG Rapture GT-AXE11000 from v3.0.0.4.386.45850
  • ROG Rapture GT-AX11000 Call of Duty Black Ops 4 from v3.0.0.4.386.44266
  • RT-AX3000 from v3.0.0.4.386.45674
  • RT-AX55 from v3.0.0.4.386.45375
  • RT-AX56U from v3.0.0.4.386.45898
  • RT-AX56U_V2 from v3.0.0.4.386.45375
  • RT-AX58U from v3.0.0.4.386.45674
  • RT-AX68U from v3.0.0.4.386.45911
  • RT-AX82U from v3.0.0.4.386.45375
  • RT-AX82U GUNDAM EDITION from v3.0.0.4.386.45375
  • RT-AX86 Series (RT-AX86U/RT-AX86S) from v3.0.0.4.386.45375
  • RT-AX86U ZAKU II EDITION from v3.0.0.4.386.45375
  • RT-AX88U from v3.0.0.4.386.44266
  • RT-AX92U from v3.0.0.4.386.45898
  • DSL-AX82U from v3.0.0.4.386.45660
  • TUF Gaming AX5400 (TUF-AX5400) from v3.0.0.4.386.45407
  • ASUS ZenWiFi XD6 from v3.0.0.4.386.45674
  • ASUS ZenWiFi AX (XT8) from v3.0.0.4.386.45898
  • TUF Gaming AX3000 from v3.0.0.4.386.45898

CVE-2021-41753 refers to D-Link products.

  • DIR-X1560 from v1.04B04
  • DIR-X6060 from v1.11B04

CVE-2021-40288 refers to TP-Link product(s).

  • AX10v1 from V1_211014

MediaTek chipset solutions patched for 11 to 13 attacks

CVE-2021-41788 refers to MediaTek products.

Acknowledgments

We would like to thank TWCERT/CC for their assistance into communicating with each affected vendor under their scope.

Security Advisories

SAEWPA3DoSExploitAttackSecurityIEEE 802.11Wi-Fi