← Back

CVE-2019-9494

nvd nist
Published: Apr 17, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

Affected (24)

Show all products
2 products
Hostapd
Wpa Supplicant
1 product
Fedora
2 products
Backports Sle
Leap
2 products
Radius Server
Router Manager
1 product
Freebsd
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.7
Up to 2.7
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 28
Version 29
Version 30
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.0 sp1
Version 15.1
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0
Before 1.2.3-8087
Configuration E
14 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 11.2
Version 11.2 p2
Version 11.2 p3
Version 11.2 p4
Version 11.2 p5
Version 11.2 p6
Version 11.2 p7
Version 11.2 p8
Version 11.2 p9
Version 11.2 rc3
Version 12.0
Version 12.0 p1
Version 12.0 p2
Version 12.0 p3

References (18)

Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
PatchVendor Advisory
Source: cret@cert.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.