CVE-2019-11555

Modified
Published: 26 Apr 2019, 21:16
Last modified:04 Aug 2024, 22:55

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
5.9 MEDIUM
v3.0 (nvd)
EPSS Score
9.38% LOW
9% probability +0.30%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Apr 2019, 21:16
Published
Vulnerability first disclosed
04 Aug 2024, 22:55
Last Modified
Vulnerability information updated

Description

The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.

CVSS Metrics

  • v3.0MEDIUMScore: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 9.38% Percentile: 93%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • w1.fihostapd

    < 2.8

  • w1.fiwpa_supplicant

    < 2.8

References (15)