PT-2019-17446 · Hostap+2 · Hostapd+2

Mark Leonard

+1

·

Published

2018-12-18

·

Updated

2022-06-17

·

CVE-2019-5062

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions hostapd version 2.6
Description An issue exists in the 802.11w security state handling for connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of service.
Recommendations For hostapd version 2.6, consider disabling the 802.11w security feature as a temporary workaround until a patch is available. Restrict access to the network to minimize the risk of exploitation. Avoid using 802.11w sessions in the affected hostapd version until the issue is resolved.

Fix

DoS

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2871
CVE-2019-5062

Affected Products

Alt Linux
Debian
Hostapd