CVE-2019-9498

Modified
Published: 17 Apr 2019, 13:31
Last modified:04 Aug 2024, 21:54

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.1 HIGH
v3.1 (nvd)
EPSS Score
0.79% LOW
1% probability -0.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Apr 2019, 13:31
Published
Vulnerability first disclosed
04 Aug 2024, 21:54
Last Modified
Vulnerability information updated

Description

The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or learning the password. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.79% Percentile: 74%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

  • CWE-346Origin Validation Error

    The product does not properly verify that the source of data or communication is valid.

Affected Systems

  • debiandebian_linux

    8.0

  • fedoraprojectfedora

    28 | 29 | 30

  • freebsdfreebsd

    ≥ 11.0, ≤ 11.1 | 11.2 | 11.2:p13 | 11.2:p2 | 11.2:p3 | 11.2:p4 | 11.2:p5 | 11.2:p6 | 11.2:p7 | 11.2:p8 | 11.2:p9 | 12.0 | 12.0:p1 | 12.0:p2 | 12.0:p3

  • opensusebackports_sle

    15.0 | 15.0:sp1

  • opensuseleap

    15.1

  • synologyradius_server

    3.0

  • synologyrouter_manager

    1.2

  • w1.fihostapd

    ≤ 2.4 | ≥ 2.5, ≤ 2.7

  • w1.fiwpa_supplicant

    ≤ 2.4 | ≥ 2.5, ≤ 2.7

  • wi-fi alliancehostapd with eap-pwd support

    2.7

  • wi-fi alliancehostapd with sae support

    2.4

  • wi-fi alliancewpa_supplicant with eap-pwd support

    2.7

  • wi-fi alliancewpa_supplicant with sae support

    2.4

References (9)