PT-2019-6324 · Linux+2 · Hostapd+2

Mitchell Frank

·

Published

2018-12-18

·

Updated

2022-06-17

·

CVE-2019-5061

CVSS v3.1

7.4

High

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions hostapd version 2.6
Description A denial-of-service issue exists where an attacker could trigger an access point to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial of service scenarios, such as causing CAM table attacks or leading to traffic flapping if faking already existing clients in other nearby access points of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this issue.
Recommendations For hostapd version 2.6, consider disabling the authentication process temporarily until a patch is available to prevent exploitation. Restrict access to nearby access points to minimize the risk of traffic flapping. Avoid using forged Authentication and Association Request packets in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

DoS

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2871
BDU:2023-01659
CVE-2019-5061

Affected Products

Alt Linux
Astra Linux
Hostapd