W1.fi
w1.fi
50 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (50)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. Th...Show more |
5Fedoraproject FreebsdOpensuse+2 more8Backports Sle FedoraFreebsd+5 moreJun 17, 2026 Apr 17, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information f...Show more |
hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call. |
3Canonical DebianW1.fi3Debian Linux Ubuntu LinuxWpa SupplicantNov 21, 2024 Aug 8, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the A...Show more |
2Debian W1.fi2Debian Linux Wpa SupplicantNov 21, 2024 Feb 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL...Show more |
2Debian W1.fi2Debian Linux Wpa SupplicantNov 21, 2024 Feb 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration p...Show more |
2Debian W1.fi2Debian Linux Wpa SupplicantNov 21, 2024 Feb 21, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attac...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 6.8 MEDIUM· v3 5.4 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 6.8 MEDIUM· v3 5.4 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof fra...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within ra...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames fr...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames fro...Show more |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients. |
7Canonical DebianFreebsd+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Oct 17, 2017 N/A· v4 6.8 MEDIUM· v3 5.4 MEDIUM· v2 Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames...Show more |
wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle attack. |
2Canonical W1.fi3Hostapd Ubuntu LinuxWpa SupplicantMay 6, 2026 May 9, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS ope...Show more |
2Opensuse W1.fi3Hostapd OpensuseWpa SupplicantMay 6, 2026 Nov 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote attackers to cause a denial of service (process crash or infinite loop) via a large payload length fie...Show more |