PT-2019-2183 · Wpa Supplicant+5 · Wpa Supplicant+5

Published

2019-04-10

·

Updated

2024-06-15

·

CVE-2019-9499

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpa supplicant versions prior to and including 2.4 wpa supplicant versions prior to and including 2.7 hostapd with SAE support prior to and including version 2.4 hostapd with EAP-pwd support prior to and including version 2.7
Description The issue is related to the EAP-PWD protocol component in wpa supplicant, which is used for wireless device certification. It involves incorrect validation of scalar and element values in the EAP-pwd-Commit imported elements. This can be exploited by a remote attacker to compromise data integrity and confidentiality or cause a denial of service. An attacker may complete authentication, session key, and control of the data connection with a client.
Recommendations For wpa supplicant versions prior to and including 2.4, consider disabling SAE support until a patch is available. For wpa supplicant versions prior to and including 2.7, consider disabling EAP-pwd support until a patch is available. For hostapd with SAE support prior to and including version 2.4, consider disabling SAE support until a patch is available. For hostapd with EAP-pwd support prior to and including version 2.7, consider disabling EAP-pwd support until a patch is available. As a temporary workaround, restrict access to the EAP-pwd-Commit element to minimize the risk of exploitation.

Fix

Improper Authentication

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2497
ALT-PU-2019-2498
ALT-PU-2019-2554
ALT-PU-2020-3139
ALT-PU-2022-1980
BDU:2019-01949
CVE-2019-9499
DLA-1867-1
DSA-4430-1
OPENSUSE-SU-2020:0222-1
OPENSUSE-SU-2020:2053-1
OPENSUSE-SU-2020:2059-1
OPENSUSE-SU-2020_0222-1
OPENSUSE-SU-2020_2053-1
OPENSUSE-SU-2020_2059-1
OPENSUSE-SU-2024:10846-1
OPENSUSE-SU-2024:11515-1
SUSE-SU-2020:3380-1
SUSE-SU-2020:3424-1
SUSE-SU-2022:1853-1
USN-3944-1

Affected Products

Alt Linux
Freebsd
Suse
Ubuntu
Hostapd
Wpa Supplicant