← Back

CVE-2019-9498

nvd nist
Published: Apr 17, 2019Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or learning the password. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.

Affected (28)

Show all products
2 products
Hostapd
Wpa Supplicant
1 product
Fedora
2 products
Backports Sle
Leap
1 product
Debian Linux
2 products
Radius Server
Router Manager
1 product
Freebsd
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
W1.fi
Up to 2.4
From 2.5 to 2.7
W1.fi
Up to 2.4
From 2.5 to 2.7
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 28
Version 29
Version 30
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.0 sp1
Version 15.1
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0
Version 1.2
Configuration F
15 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
From 11.0 to 11.1
Version 11.2
Version 11.2 p13
Version 11.2 p2
Version 11.2 p3
Version 11.2 p4
Version 11.2 p5
Version 11.2 p6
Version 11.2 p7
Version 11.2 p8
Version 11.2 p9
Version 12.0
Version 12.0 p1
Version 12.0 p2
Version 12.0 p3

References (18)

Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
Mailing ListThird Party Advisory
Source: cret@cert.org
PatchVendor Advisory
Source: cret@cert.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.