PT-2019-6124 · Linux+4 · Wpa Supplicant+5

Published

2019-04-10

·

Updated

2024-06-15

·

CVE-2019-9496

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions hostapd versions with SAE support wpa supplicant versions prior to and including 2.7
Description The issue is related to an invalid authentication sequence that could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message. This can be exploited by an attacker to force the hostapd process to terminate, resulting in a denial of service attack. The problem is associated with the implementation of the SAE function in wpa supplicant for WPA wireless communication device certification, which is linked to incorrect authentication sequences.
Recommendations For hostapd with SAE support, consider disabling SAE support as a temporary workaround until a patch is available. For wpa supplicant versions prior to and including 2.7, update to a version later than 2.7 to resolve the issue. As a temporary mitigation measure for wpa supplicant, restrict the use of SAE functionality until an update can be applied.

Fix

DoS

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2497
ALT-PU-2019-2498
ALT-PU-2019-2554
ALT-PU-2020-3139
ALT-PU-2022-1980
BDU:2021-05847
CVE-2019-9496
OPENSUSE-SU-2020:0222-1
OPENSUSE-SU-2020_0222-1
OPENSUSE-SU-2024:10846-1

Affected Products

Alt Linux
Fortios
Freebsd
Suse
Hostapd
Wpa Supplicant