CVE-2019-9496

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
17/04/2019
Last modified:
07/11/2023

Description

An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:* 2.7 (including)
cpe:2.3:a:w1.fi:wpa_supplicant:*:*:*:*:*:*:*:* 2.7 (including)
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*