PT-2019-2181 · Hostap+5 · Hostapd+5

Publicado

2019-04-10

·

Atualizado

2024-06-15

·

CVE-2019-9497

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hostapd with SAE support versions prior to 2.4 hostapd with EAP-pwd support versions prior to 2.7 wpa supplicant with SAE support versions prior to 2.4 wpa supplicant with EAP-pwd support versions prior to 2.7
Description The issue is related to the implementations of EAP-PWD in hostapd EAP Server and wpa supplicant EAP Peer, which do not validate the scalar and element values in EAP-pwd-Commit. This may allow an attacker to complete EAP-PWD authentication without knowing the password, potentially affecting the integrity and confidentiality of data, as well as causing a denial of service. However, the attacker will not be able to derive the session key or complete the key exchange unless the crypto library does not implement additional checks for the EC point.
Recommendations For hostapd with SAE support versions prior to 2.4, update to a version later than 2.4 to resolve the issue. For hostapd with EAP-pwd support versions prior to 2.7, update to a version later than 2.7 to resolve the issue. For wpa supplicant with SAE support versions prior to 2.4, update to a version later than 2.4 to resolve the issue. For wpa supplicant with EAP-pwd support versions prior to 2.7, update to a version later than 2.7 to resolve the issue.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2497
ALT-PU-2019-2498
ALT-PU-2019-2554
ALT-PU-2020-3139
ALT-PU-2022-1980
BDU:2019-01947
CVE-2019-9497
DLA-1867-1
DSA-4430-1
OPENSUSE-SU-2020:0222-1
OPENSUSE-SU-2020:2053-1
OPENSUSE-SU-2020:2059-1
OPENSUSE-SU-2020_0222-1
OPENSUSE-SU-2020_2053-1
OPENSUSE-SU-2020_2059-1
OPENSUSE-SU-2024:10846-1
OPENSUSE-SU-2024:11515-1
SUSE-SU-2020:3380-1
SUSE-SU-2020:3424-1
SUSE-SU-2022:1853-1
USN-3944-1

Produtos afetados

Alt Linux
Freebsd
Suse
Ubuntu
Hostapd
Wpa Supplicant