PT-2019-6324 · Linux+2 · Hostapd+2
Mitchell Frank
·
Published
2018-12-18
·
Updated
2022-06-17
·
CVE-2019-5061
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
hostapd version 2.6
Description
A denial-of-service issue exists where an attacker could trigger an access point to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial of service scenarios, such as causing CAM table attacks or leading to traffic flapping if faking already existing clients in other nearby access points of the same wireless infrastructure. An attacker can forge
Authentication and Association Request packets to trigger this issue.Recommendations
For hostapd version 2.6, consider disabling the authentication process temporarily until a patch is available to prevent exploitation. Restrict access to nearby access points to minimize the risk of traffic flapping. Avoid using forged
Authentication and Association Request packets in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Fix
DoS
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Hostapd