ZeroHour

CVE-2019-9496

CVSS 3.0
7.5 high
EPSS
5%p91
Published
()
Modified
Description

An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

Vendors
w1.fifedoraproject
Products
hostapd, wpa supplicant, fedora
Weakness
CWE-642, CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.