CVE-2019-9497

Modified
Published: 17 Apr 2019, 13:31
Last modified:04 Aug 2024, 21:54

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.1 HIGH
v3.0 (nvd)
EPSS Score
11.47% MEDIUM
11% probability +3.29%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Apr 2019, 13:31
Published
Vulnerability first disclosed
04 Aug 2024, 21:54
Last Modified
Vulnerability information updated

Description

The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authentication without knowing the password. However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key or complete the key exchange. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.

CVSS Metrics

  • v3.0HIGHScore: 8.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 11.47% Percentile: 94%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

  • CWE-301Reflection Attack in an Authentication Protocol

    Simple authentication protocols are subject to reflection attacks if a malicious user can use the target machine to impersonate a trusted user.

Affected Systems

  • fedoraprojectfedora

    28 | 29 | 30

  • w1.fihostapd

    ≤ 2.4 | ≥ 2.5, ≤ 2.7

  • w1.fiwpa_supplicant

    ≤ 2.4 | ≥ 2.5, ≤ 2.7

  • wi-fi alliancehostapd with eap-pwd support

    2.7

  • wi-fi alliancehostapd with sae support

    2.4

  • wi-fi alliancewpa_supplicant with eap-pwd support

    2.7

  • wi-fi alliancewpa_supplicant with sae support

    2.4

References (10)