PT-2019-2183 · Wpa Supplicant+5 · Wpa Supplicant+5
Published
2019-04-10
·
Updated
2024-06-15
·
CVE-2019-9499
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wpa supplicant versions prior to and including 2.4
wpa supplicant versions prior to and including 2.7
hostapd with SAE support prior to and including version 2.4
hostapd with EAP-pwd support prior to and including version 2.7
Description
The issue is related to the EAP-PWD protocol component in wpa supplicant, which is used for wireless device certification. It involves incorrect validation of scalar and element values in the
EAP-pwd-Commit imported elements. This can be exploited by a remote attacker to compromise data integrity and confidentiality or cause a denial of service. An attacker may complete authentication, session key, and control of the data connection with a client.Recommendations
For wpa supplicant versions prior to and including 2.4, consider disabling SAE support until a patch is available.
For wpa supplicant versions prior to and including 2.7, consider disabling EAP-pwd support until a patch is available.
For hostapd with SAE support prior to and including version 2.4, consider disabling SAE support until a patch is available.
For hostapd with EAP-pwd support prior to and including version 2.7, consider disabling EAP-pwd support until a patch is available.
As a temporary workaround, restrict access to the
EAP-pwd-Commit element to minimize the risk of exploitation.Fix
Improper Authentication
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Freebsd
Suse
Ubuntu
Hostapd
Wpa Supplicant