CVE-2019-13456
published 2019-12-03CVE-2019-13456: In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the…
PriorityP431medium6.5CVSS 3.1
AVAACLPRNUINSUCHINAN
EPSS
1.63%
73.6th percentile
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 3.0.20+dfsg-1 (bookworm) | freeradius 3.0.20+dfsg-1 (bookworm) |
| freeradius | freeradius | >= 0 < 3.0.20+dfsg-1 | 3.0.20+dfsg-1 |
| freeradius | freeradius | >= 0 < 3.0.20+dfsg-1 | 3.0.20+dfsg-1 |
| freeradius | freeradius | >= 0 < 3.0.20+dfsg-1 | 3.0.20+dfsg-1 |
| freeradius | freeradius | >= 0 < 3.0.20+dfsg-1 | 3.0.20+dfsg-1 |
| freeradius | freeradius | 3.0.0 – 3.0.19 | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qwvf-9vg7-643x: In FreeRADIUS 3
ghsa_unreviewed·2022-05-24·CVSS 5.9
CVE-2019-13456 [MEDIUM] CWE-200 GHSA-qwvf-9vg7-643x: In FreeRADIUS 3
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
OSV
CVE-2019-13456: In FreeRADIUS 3
osv·2019-12-03·CVSS 6.5
CVE-2019-13456 [MEDIUM] CVE-2019-13456: In FreeRADIUS 3
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
Red Hat
freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations
vendor_redhat·2019-08-03·CVSS 6.5
CVE-2019-13456 [MEDIUM] CWE-200 freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations
freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
An information leak was discovered in the implementation of EAP-pwd in freeradius. An attacker could initiate several EAP-pwd handshakes to leak information, which can then be used to recover the user's WiFi password by performing dictionary and brute-force attacks.
Statement: This issue did not affect the versions of freeradius as shipped with Red Ha
Debian
CVE-2019-13456: freeradius - In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes ...
vendor_debian·2019·CVSS 6.5
CVE-2019-13456 [MEDIUM] CVE-2019-13456: freeradius - In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes ...
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
Scope: local
bookworm: resolved (fixed in 3.0.20+dfsg-1)
bullseye: resolved (fixed in 3.0.20+dfsg-1)
forky: resolved (fixed in 3.0.20+dfsg-1)
sid: resolved (fixed in 3.0.20+dfsg-1)
trixie: resolved (fixed in 3.0.20+dfsg-1)
No detection rules found.
No public exploits indexed.
HackerOne
Dragonblood: Design and Implementation Flaws in WPA3 and EAP-pwd
hackerone·2020-05-05·CVSS 9.8
[CRITICAL] Dragonblood: Design and Implementation Flaws in WPA3 and EAP-pwd
Dragonblood: Design and Implementation Flaws in WPA3 and EAP-pwd
Full background information is at [our website](wpa3.mathyvanhoef.com) and detailed information can be found in our [research paper](https://eprint.iacr.org/2019/383).
# Vulnerability Summary
## First Disclosure
Summarized, the Dragonfly handshake of WPA3 and EAP-pwd is supposed to prevent dictionary attacks. However, we discovered design flaws that still enable an adversary to perform dictionary attacks. In particular, we discovered the following design flaws in WPA3 and EAP-pwd:
- Against EAP-pwd, a timing leak exists for all supported elliptic curves. An adversary within range of the victim can induce clients to connect to the adversary's Access Point (AP) and exploit this timing leak. The leaked information can be use
Bugzilla
CVE-2019-13456 freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations [fedora-all]
bugzilla·2019-08-06·CVSS 6.5
CVE-2019-13456 [MEDIUM] CVE-2019-13456 freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations [fedora-all]
CVE-2019-13456 freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2019-13456 freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations
bugzilla·2019-08-06·CVSS 6.5
CVE-2019-13456 [MEDIUM] CVE-2019-13456 freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations
CVE-2019-13456 freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations
A flaw was found in the implementation of EAP-pwd in FreeRADIUS. An attacker could initiate several EAP-pwd handshakes to leak information, which can then be used to recover the user's WiFi password by performing dictionary and brute-force attacks.
References:
https://wpa3.mathyvanhoef.com/#new
Discussion:
Created freeradius tracking bugs for this issue:
Affects: fedora-all [bug 1737664]
---
Upstream patch:
https://github.com/FreeRADIUS/freeradius-server/commit/3ea2a5a026e73d81cd9a3e9bbd4300c433004bfa
---
EAP-PWD support was first added in freeradius 3.0.0, so earlier versions as shipped in Red Hat Enterprise Linux 6 and earlier are not affected.
---
Statement:
This issue
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00039.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1737663https://freeradius.org/security/https://github.com/FreeRADIUS/freeradius-server/commit/3ea2a5a026e73d81cd9a3e9bbd4300c433004bfahttps://wpa3.mathyvanhoef.comhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00039.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1737663https://freeradius.org/security/https://github.com/FreeRADIUS/freeradius-server/commit/3ea2a5a026e73d81cd9a3e9bbd4300c433004bfahttps://wpa3.mathyvanhoef.com
2019-12-03
Published