PT-2024-5576 · Unknown+4 · Wpa Supplicant+4

Marc Deslauriers

+3

·

Published

2024-05-30

·

Updated

2025-11-18

·

CVE-2024-5290

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpa supplicant (affected versions not specified)
Description The issue is related to an uncontrolled search path element in wpa supplicant, allowing a local unprivileged attacker to escalate privileges to the user that wpa supplicant runs as, usually root. Membership in the netdev group or access to the dbus interface of wpa supplicant allows an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa supplicant process. The estimated number of potentially affected devices is in the millions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-06261
CVE-2024-5290
DSA-5739-1
OESA-2024-2142
USN-6945-1

Affected Products

Astra Linux
Linuxmint
Red Os
Ubuntu
Wpa Supplicant