CVE-2022-23304 | wpa_supplicant/hostapd up to 2.9 EAP-pwd information exposure (EUVD-2022-28389 / Nessus ID 218383)
A vulnerability classified as problematic was found in wpa_supplicant and hostapd up to 2.9. Affected is an unknown function of the component EAP-pwd. The manipulation results in information exposure through discrepancy.
This vulnerability is identified as CVE-2022-23304. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is advised.