PT-2019-6123 · Hostap+5 · Hostapd+5

Publicado

2019-04-10

·

Atualizado

2024-06-15

·

CVE-2019-9494

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions hostapd with SAE support versions prior to 2.7 wpa supplicant with SAE support versions prior to 2.7
Description The issue is related to the implementation of SAE in hostapd and wpa supplicant, which is vulnerable to side channel attacks due to observable timing differences and cache access patterns. This allows a remote attacker to potentially gain access to confidential data by exploiting the side channel attack for full password recovery.
Recommendations For hostapd with SAE support versions prior to 2.7, update to a version later than 2.7 to resolve the issue. For wpa supplicant with SAE support versions prior to 2.7, update to a version later than 2.7 to resolve the issue.

Correção

DoS

Information Disclosure

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2497
ALT-PU-2019-2498
ALT-PU-2019-2554
ALT-PU-2020-3139
ALT-PU-2022-1980
BDU:2021-05846
CVE-2019-9494
DSA-4430-1
MGASA-2019-0229
OPENSUSE-SU-2020:0222-1
OPENSUSE-SU-2020:2053-1
OPENSUSE-SU-2020:2059-1
OPENSUSE-SU-2020_0222-1
OPENSUSE-SU-2020_2053-1
OPENSUSE-SU-2020_2059-1
OPENSUSE-SU-2024:10846-1
OPENSUSE-SU-2024:11515-1
SUSE-SU-2020:3380-1
SUSE-SU-2020:3424-1
SUSE-SU-2022:1853-1

Produtos afetados

Alt Linux
Fortios
Freebsd
Suse
Hostapd
Wpa Supplicant