PT-2019-5501 · Linux+3 · Wpa Supplicant+4

Published

2019-08-03

·

Updated

2024-06-15

·

CVE-2019-13377

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions hostapd and wpa supplicant versions 2.x through 2.8
Description The issue is related to side-channel attacks due to observable timing differences and cache access patterns when Brainpool curves are used in the implementations of SAE and EAP-pwd. This can allow an attacker to gain leaked information that can be used for full password recovery. The vulnerability is also related to errors in security mechanisms in the hostapd program, which can be exploited by a remote attacker to obtain credentials. Additionally, a new method of attack on wireless networks using WPA3 technology has been identified, allowing an attacker to obtain information about password characteristics that can be used for offline password guessing.
Recommendations For hostapd and wpa supplicant versions 2.x through 2.8, consider disabling the use of Brainpool curves as a temporary workaround until a patch is available. Restrict access to the EAP-pwd protocol to minimize the risk of exploitation. Avoid using the vulnerable implementations of SAE and EAP-pwd until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2497
ALT-PU-2020-3139
ALT-PU-2022-1980
BDU:2020-03318
CVE-2019-13377
DSA-4538-1
MGASA-2019-0229
OESA-2021-1019
OPENSUSE-SU-2020:2053-1
OPENSUSE-SU-2020:2059-1
OPENSUSE-SU-2020_2053-1
OPENSUSE-SU-2020_2059-1
OPENSUSE-SU-2024:11515-1
SUSE-SU-2020:3380-1
SUSE-SU-2020:3424-1
SUSE-SU-2022:1853-1
USN-4098-1

Affected Products

Alt Linux
Suse
Ubuntu
Hostapd
Wpa Supplicant