[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-9497Date: (C)2019-06-19   (M)2023-12-22


The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authentication without knowing the password. However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key or complete the key exchange. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.1CVSS Score : 6.8
Exploit Score: 2.2Exploit Score: 8.6
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
https://seclists.org/bugtraq/2019/May/40
FEDORA-2019-d03bae77f5
FEDORA-2019-eba1109acd
FEDORA-2019-f409af9fbe
FreeBSD-SA-19:03
https://lists.debian.org/debian-lts-announce/2019/07/msg00030.html
http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
https://w1.fi/security/2019-4/
https://www.synology.com/security/advisory/Synology_SA_19_16
openSUSE-SU-2020:0222

CPE    2
cpe:/a:w1.fi:hostapd
cpe:/a:w1.fi:wpa_supplicant
CWE    1
CWE-287
OVAL    11
oval:org.secpod.oval:def:54266
oval:org.secpod.oval:def:54399
oval:org.secpod.oval:def:54400
oval:org.secpod.oval:def:54504
...

© SecPod Technologies