An IoT badge reader used at county building doors has a published CVE in its Wi-Fi module. How should WLAN vulnerability scope treat that finding?
Select an answer to reveal the explanation.
Short Explanation
WLAN risk is not 'APs only.' That door badge reader's Wi-Fi chip can be a soft underbelly on the same air the county trusts—clients and specialty gear stay in the CVE hunt.
Full Explanation
WLAN-related vulnerability scope includes clients and specialty wireless devices, not only APs and controllers. An IoT badge reader with a Wi-Fi module CVE can introduce exposure on the same RF and sometimes the same VLANs as corporate WLAN. Limiting CVE tracking to infrastructure radios alone understates Domain 2.1.1 coverage.