PT-2019-6123 · Hostap+5 · Hostapd+5
Published
2019-04-10
·
Updated
2024-06-15
·
CVE-2019-9494
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
hostapd with SAE support versions prior to 2.7
wpa supplicant with SAE support versions prior to 2.7
Description
The issue is related to the implementation of SAE in hostapd and wpa supplicant, which is vulnerable to side channel attacks due to observable timing differences and cache access patterns. This allows a remote attacker to potentially gain access to confidential data by exploiting the side channel attack for full password recovery.
Recommendations
For hostapd with SAE support versions prior to 2.7, update to a version later than 2.7 to resolve the issue.
For wpa supplicant with SAE support versions prior to 2.7, update to a version later than 2.7 to resolve the issue.
Fix
DoS
Information Disclosure
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Fortios
Freebsd
Suse
Hostapd
Wpa Supplicant