PT-2019-2183 · Wpa Supplicant+5 · Wpa Supplicant+5

Publicado

2019-04-10

·

Atualizado

2024-06-15

·

CVE-2019-9499

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpa supplicant versions prior to and including 2.4 wpa supplicant versions prior to and including 2.7 hostapd with SAE support prior to and including version 2.4 hostapd with EAP-pwd support prior to and including version 2.7
Description The issue is related to the EAP-PWD protocol component in wpa supplicant, which is used for wireless device certification. It involves incorrect validation of scalar and element values in the EAP-pwd-Commit imported elements. This can be exploited by a remote attacker to compromise data integrity and confidentiality or cause a denial of service. An attacker may complete authentication, session key, and control of the data connection with a client.
Recommendations For wpa supplicant versions prior to and including 2.4, consider disabling SAE support until a patch is available. For wpa supplicant versions prior to and including 2.7, consider disabling EAP-pwd support until a patch is available. For hostapd with SAE support prior to and including version 2.4, consider disabling SAE support until a patch is available. For hostapd with EAP-pwd support prior to and including version 2.7, consider disabling EAP-pwd support until a patch is available. As a temporary workaround, restrict access to the EAP-pwd-Commit element to minimize the risk of exploitation.

Correção

Improper Authentication

Origin Validation Error

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2497
ALT-PU-2019-2498
ALT-PU-2019-2554
ALT-PU-2020-3139
ALT-PU-2022-1980
BDU:2019-01949
CVE-2019-9499
DLA-1867-1
DSA-4430-1
OPENSUSE-SU-2020:0222-1
OPENSUSE-SU-2020:2053-1
OPENSUSE-SU-2020:2059-1
OPENSUSE-SU-2020_0222-1
OPENSUSE-SU-2020_2053-1
OPENSUSE-SU-2020_2059-1
OPENSUSE-SU-2024:10846-1
OPENSUSE-SU-2024:11515-1
SUSE-SU-2020:3380-1
SUSE-SU-2020:3424-1
SUSE-SU-2022:1853-1
USN-3944-1

Produtos afetados

Alt Linux
Freebsd
Suse
Ubuntu
Hostapd
Wpa Supplicant