ZeroHour

CVE-2018-14526

CVSS 3.0
6.5 medium
EPSS
1%p72
Published
()
Modified
Description

An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.

Vendors
canonicaldebianw1.fi
Products
ubuntu linux, debian linux, wpa supplicant
Weakness
CWE-924
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.