← Back

CVE-2019-9495

nvd nist
Published: Apr 17, 2019Modified: Jun 17, 2026

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.

Affected (25)

Show all products
2 products
Hostapd
Wpa Supplicant
1 product
Fedora
2 products
Backports Sle
Leap
1 product
Debian Linux
2 products
Radius Server
Router Manager
1 product
Freebsd
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.7
Up to 2.7
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 28
Version 29
Version 30
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.0 sp1
Version 15.1
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Version 3.0
Before 1.2.3-8017
Configuration E
14 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 11.2
Version 11.2 p2
Version 11.2 p3
Version 11.2 p4
Version 11.2 p5
Version 11.2 p6
Version 11.2 p7
Version 11.2 p8
Version 11.2 p9
Version 11.2 rc3
Version 12.0
Version 12.0 p1
Version 12.0 p2
Version 12.0 p3

References (20)

Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
PatchVendor Advisory
Source: cret@cert.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.