The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.
Conclusion & alert: CVE-2022-47522 is rated Exploit Available (59.1/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.90%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 12.58% | 0.90% | -11.69% |
| 2 | 2026-05-30 | 15.69% | 12.58% | -3.11% |
| 3 | 2026-05-03 | — | 15.69% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
1.6 | 5.9 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
1.6 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
suse
|
high | — | https://www.suse.com/security/cve/CVE-2022-47522/ |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| ieee | ieee_802.11 | — | cpe:2.3:a:ieee:ieee_802.11:*:*:*:*:*:*:*:* |
| sonicwall | tz670_firmware | — | cpe:2.3:o:sonicwall:tz670_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz570_firmware | — | cpe:2.3:o:sonicwall:tz570_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz570p_firmware | — | cpe:2.3:o:sonicwall:tz570p_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz570w_firmware | — | cpe:2.3:o:sonicwall:tz570w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz470_firmware | — | cpe:2.3:o:sonicwall:tz470_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz470w_firmware | — | cpe:2.3:o:sonicwall:tz470w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz370_firmware | — | cpe:2.3:o:sonicwall:tz370_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz370w_firmware | — | cpe:2.3:o:sonicwall:tz370w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz270_firmware | — | cpe:2.3:o:sonicwall:tz270_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz270w_firmware | — | cpe:2.3:o:sonicwall:tz270w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz600_firmware | — | cpe:2.3:o:sonicwall:tz600_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz600p_firmware | — | cpe:2.3:o:sonicwall:tz600p_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz500_firmware | — | cpe:2.3:o:sonicwall:tz500_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz500w_firmware | — | cpe:2.3:o:sonicwall:tz500w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz400_firmware | — | cpe:2.3:o:sonicwall:tz400_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz400w_firmware | — | cpe:2.3:o:sonicwall:tz400w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz350_firmware | — | cpe:2.3:o:sonicwall:tz350_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz350w_firmware | — | cpe:2.3:o:sonicwall:tz350w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz300_firmware | — | cpe:2.3:o:sonicwall:tz300_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz300p_firmware | — | cpe:2.3:o:sonicwall:tz300p_firmware:-:*:*:*:*:*:*:* |
| sonicwall | tz300w_firmware | — | cpe:2.3:o:sonicwall:tz300w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | soho_250_firmware | — | cpe:2.3:o:sonicwall:soho_250_firmware:-:*:*:*:*:*:*:* |
| sonicwall | soho_250w_firmware | — | cpe:2.3:o:sonicwall:soho_250w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sonicwave_231c_firmware | — | cpe:2.3:o:sonicwall:sonicwave_231c_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sonicwave_224w_firmware | — | cpe:2.3:o:sonicwall:sonicwave_224w_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sonicwave_432o_firmware | — | cpe:2.3:o:sonicwall:sonicwave_432o_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sonicwave_621_firmware | — | cpe:2.3:o:sonicwall:sonicwave_621_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sonicwave_641_firmware | — | cpe:2.3:o:sonicwall:sonicwave_641_firmware:-:*:*:*:*:*:*:* |
| sonicwall | sonicwave_681_firmware | — | cpe:2.3:o:sonicwall:sonicwave_681_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://papers.mathyvanhoef.com/usenix2023-wifi.pdf | Exploit Technical Description Third Party Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0006 | Third Party Advisory |
| https://www.freebsd.org/security/advisories/FreeBSD-SA-23:11.wifi.asc | |
| https://www.wi-fi.org/discover-wi-fi/passpoint | Not Applicable |