DEBIAN-CVE-2019-9496
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 17 Apr 2019, 14:29
Last modified:28 Apr 2026, 20:21
Vulnerability Summary
Overall Risk (default)
medium
30/100 CVSS Score
7.5 HIGH
3.0 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
17 Apr 2019, 14:29
Published
Vulnerability first disclosed
28 Apr 2026, 20:21
Last Modified
Vulnerability information updated
Description
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
CVSS Metrics
- v3.0•HIGH•Score: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Systems
- debian•wpa
< 2:2.7+git20190128+0c1e29f-4 | < 2:2.7+git20190128+0c1e29f-4 | < 2:2.7+git20190128+0c1e29f-4 | < 2:2.7+git20190128+0c1e29f-4