PT-2019-6123 · Hostap+5 · Hostapd+5

Published

2019-04-10

·

Updated

2024-06-15

·

CVE-2019-9494

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions hostapd with SAE support versions prior to 2.7 wpa supplicant with SAE support versions prior to 2.7
Description The issue is related to the implementation of SAE in hostapd and wpa supplicant, which is vulnerable to side channel attacks due to observable timing differences and cache access patterns. This allows a remote attacker to potentially gain access to confidential data by exploiting the side channel attack for full password recovery.
Recommendations For hostapd with SAE support versions prior to 2.7, update to a version later than 2.7 to resolve the issue. For wpa supplicant with SAE support versions prior to 2.7, update to a version later than 2.7 to resolve the issue.

Fix

DoS

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2497
ALT-PU-2019-2498
ALT-PU-2019-2554
ALT-PU-2020-3139
ALT-PU-2022-1980
BDU:2021-05846
CVE-2019-9494
DSA-4430-1
MGASA-2019-0229
OPENSUSE-SU-2020:0222-1
OPENSUSE-SU-2020:2053-1
OPENSUSE-SU-2020:2059-1
OPENSUSE-SU-2020_0222-1
OPENSUSE-SU-2020_2053-1
OPENSUSE-SU-2020_2059-1
OPENSUSE-SU-2024:10846-1
OPENSUSE-SU-2024:11515-1
SUSE-SU-2020:3380-1
SUSE-SU-2020:3424-1
SUSE-SU-2022:1853-1

Affected Products

Alt Linux
Fortios
Freebsd
Suse
Hostapd
Wpa Supplicant