CVE-2019-16275Origin Validation Error in Hostapd

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 33.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12
Latest updateMay 24

Description

hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Also affects: Debian Linux 10.0, 8.0, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 19.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-96gq-6rhf-g9x2: hostapd before 22022-05-24
OSV
CVE-2019-16275: hostapd before 22019-09-13
OSV
CVE-2019-16275: hostapd before 22019-09-12
CVEList
CVE-2019-16275: hostapd before 22019-09-12

📋Vendor Advisories

5
Ubuntu
wpa_supplicant and hostapd vulnerability2019-09-18
Ubuntu
wpa_supplicant and hostapd vulnerability2019-09-18
Red Hat
wpa_supplicant: AP mode PMF disconnection protection bypass2019-09-11
Microsoft
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service tha2019-09-10
Debian
CVE-2019-16275: wpa - hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication...2019

💬Community

4
Bugzilla
CVE-2019-16275 hostapd: wpa_supplicant: AP mode PMF disconnection protection bypass [epel-all]2019-10-30
Bugzilla
CVE-2019-16275 wpa_supplicant: AP mode PMF disconnection protection bypass [fedora-all]2019-10-30
Bugzilla
CVE-2019-16275 hostapd: wpa_supplicant: AP mode PMF disconnection protection bypass [fedora-all]2019-10-30
Bugzilla
CVE-2019-16275 wpa_supplicant: AP mode PMF disconnection protection bypass2019-10-30
CVE-2019-16275 — Origin Validation Error in Hostapd | cvebase