Understanding PEAP In-Depth
ID: c4726e3b-e310-5e7d-951d-ab9b4066447d
STIX ID: report--c4726e3b-e310-5e7d-951d-ab9b4066447d
Feed Name: SensePost Blog
Threat Score
This report details a PEAP/MSCHAPv2 implementation bug in iOS, macOS and tvOS (CVE-2019-6203) where Apple clients did not validate the MSCHAPv2 authenticator response, enabling a malicious access point to force devices to connect, capture NetNTLMv1-style challenge/response data, and facilitate further MitM attacks; the author provides deep protocol analysis, reproduction steps (hostapd-wpe), and notes Apple’s subsequent patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
