PT-2019-2181 · Hostap+5 · Hostapd+5
Published
2019-04-10
·
Updated
2024-06-15
·
CVE-2019-9497
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
hostapd with SAE support versions prior to 2.4
hostapd with EAP-pwd support versions prior to 2.7
wpa supplicant with SAE support versions prior to 2.4
wpa supplicant with EAP-pwd support versions prior to 2.7
Description
The issue is related to the implementations of EAP-PWD in hostapd EAP Server and wpa supplicant EAP Peer, which do not validate the scalar and element values in EAP-pwd-Commit. This may allow an attacker to complete EAP-PWD authentication without knowing the password, potentially affecting the integrity and confidentiality of data, as well as causing a denial of service. However, the attacker will not be able to derive the session key or complete the key exchange unless the crypto library does not implement additional checks for the EC point.
Recommendations
For hostapd with SAE support versions prior to 2.4, update to a version later than 2.4 to resolve the issue.
For hostapd with EAP-pwd support versions prior to 2.7, update to a version later than 2.7 to resolve the issue.
For wpa supplicant with SAE support versions prior to 2.4, update to a version later than 2.4 to resolve the issue.
For wpa supplicant with EAP-pwd support versions prior to 2.7, update to a version later than 2.7 to resolve the issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Freebsd
Suse
Ubuntu
Hostapd
Wpa Supplicant