The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.
Conclusion & alert: CVE-2023-52424 is rated Moderate Risk (47.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.72%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.24% | 0.72% | +0.47% |
| 2 | 2025-09-01 | 0.25% | 0.24% | -0.01% |
| 3 | 2025-08-19 | — | 0.25% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.4 | 3.1 | HIGH |
|
1.5 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-52424 |
suse
|
medium | CVE-2023-52424 severity moderate: SUSE including 7 source package names (hostapd-2.11-2.1, hostapd-2.11-bp156.2.3.1, …), 8 product×package rows across 6 product lines (SUSE Linux Enterprise Module for Basesystem 15 SP7, SUSE Linux Enterprise Server 16.0, … (6 product lines)): Fixed 8. | https://www.suse.com/security/cve/CVE-2023-52424/ |
ubuntu
|
medium | CVE-2023-52424 medium priority: Ubuntu including 1 source packages (wpa), 11 status rows across 11 suites (bionic, focal, jammy, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): deferred 7, ignored 3, needs-triage 1. | https://ubuntu.com/security/CVE-2023-52424 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||