logo

Understanding PEAP In-Depth

ID: c4726e3b-e310-5e7d-951d-ab9b4066447d

STIX ID: report--c4726e3b-e310-5e7d-951d-ab9b4066447d

Feed Name: SensePost Blog

Threat Score
50/100

Date Published: 2019-04-18

Date Updated: 2026-04-29

...
...

This report details a PEAP/MSCHAPv2 implementation bug in iOS, macOS and tvOS (CVE-2019-6203) where Apple clients did not validate the MSCHAPv2 authenticator response, enabling a malicious access point to force devices to connect, capture NetNTLMv1-style challenge/response data, and facilitate further MitM attacks; the author provides deep protocol analysis, reproduction steps (hostapd-wpe), and notes Apple’s subsequent patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.