CVE-2019-9495
published 2019-04-17CVE-2019-9495: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of…
PriorityP418low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
3.45%
87.7th percentile
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | wpa | < wpa 2:2.10-1 (bookworm) | wpa 2:2.10-1 (bookworm) |
| debian | wpa | < wpa 2:2.7+git20190128+0c1e29f-4 (bookworm) | wpa 2:2.7+git20190128+0c1e29f-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| msrc | cbl2_wpa_supplicant_2.10-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_wpa_supplicant_2.10-1_on_cbl_mariner_1.0 | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| synology | radius_server | — | — |
| synology | router_manager | < 1.2.3-8017 | 1.2.3-8017 |
| w1.fi | hostapd | < 2.10 | 2.10 |
| w1.fi | hostapd | <= 2.7 | — |
| w1.fi | wpa_supplicant | < 2.10 | 2.10 |
| w1.fi | wpa_supplicant | <= 2.7 | — |
| w1.fi | wpa_supplicant | >= 0 < 2:2.9.0-21+deb11u3 | 2:2.9.0-21+deb11u3 |
| w1.fi | wpa_supplicant | >= 0 < 2:2.7+git20190128+0c1e29f-4 | 2:2.7+git20190128+0c1e29f-4 |
| w1.fi | wpa_supplicant | >= 0 < 2:2.10-1 | 2:2.10-1 |
| w1.fi | wpa_supplicant | >= 0 < 2:2.7+git20190128+0c1e29f-4 | 2:2.7+git20190128+0c1e29f-4 |
| w1.fi | wpa_supplicant | >= 0 < 2:2.10-1 | 2:2.10-1 |
| w1.fi | wpa_supplicant | >= 0 < 2:2.7+git20190128+0c1e29f-4 | 2:2.7+git20190128+0c1e29f-4 |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_msrc9.8CRITICAL
vendor_ubuntu7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p694-q9qw-q238: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns
ghsa_unreviewed·2022-05-13·CVSS 5.9
CVE-2019-9495 [MEDIUM] CWE-203 GHSA-p694-q9qw-q238: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
GHSA
GHSA-fwqr-qx2m-vqxq: The implementations of EAP-pwd in hostapd before 2
ghsa_unreviewed·2022-02-15·CVSS 3.7
CVE-2022-23304 [LOW] CWE-203 GHSA-fwqr-qx2m-vqxq: The implementations of EAP-pwd in hostapd before 2
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
OSV
CVE-2022-23304: The implementations of EAP-pwd in hostapd before 2
osv·2022-01-17·CVSS 3.7
CVE-2022-23304 [LOW] CVE-2022-23304: The implementations of EAP-pwd in hostapd before 2
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
OSV
CVE-2019-9495: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns
osv·2019-04-17·CVSS 5.9
CVE-2019-9495 [MEDIUM] CVE-2019-9495: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
OSV
wpa vulnerabilities
osv·2019-04-10·CVSS 7.5
CVE-2019-9495 [HIGH] wpa vulnerabilities
wpa vulnerabilities
It was discovered that wpa_supplicant and hostapd were vulnerable to a
side channel attack against EAP-pwd. A remote attacker could possibly use
this issue to recover certain passwords. (CVE-2019-9495)
Mathy Vanhoef discovered that wpa_supplicant and hostapd incorrectly
validated received scalar and element values in EAP-pwd-Commit messages. A
remote attacker could possibly use this issue to perform a reflection
attack and authenticate without the appropriate password. (CVE-2019-9497,
CVE-2019-9498, CVE-2019-9499)
It was discovered that hostapd incorrectly handled obtaining random
numbers. In rare cases where the urandom device isn't available, it would
fall back to using a low-quality PRNG. This issue only affected Ubuntu
14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10
Red Hat
wpa_supplicant: EAP-pwd side-channel attacks as a result of cache access patterns
vendor_redhat·2022-01-17·CVSS 3.7
CVE-2022-23304 [LOW] CWE-924 wpa_supplicant: EAP-pwd side-channel attacks as a result of cache access patterns
wpa_supplicant: EAP-pwd side-channel attacks as a result of cache access patterns
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. The highest threat from this vulnerability is to availability, confidentiality and integrity.
Statement: Red Hat believes this vulnerability to be of moderate impact because one of the requisites for exploitation is the ability to run unprivileged code on the victim's machine; furthermore, the complexity of this attac
Microsoft
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an
vendor_msrc·2022-01-11·CVSS 9.8
CVE-2022-23304 [LOW] CWE-203 The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products
Debian
CVE-2022-23304: wpa - The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before ...
vendor_debian·2022·CVSS 3.7
CVE-2022-23304 [LOW] CVE-2022-23304: wpa - The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before ...
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
Scope: local
bookworm: resolved (fixed in 2:2.10-1)
bullseye: resolved (fixed in 2:2.9.0-21+deb11u3)
forky: resolved (fixed in 2:2.10-1)
sid: resolved (fixed in 2:2.10-1)
trixie: resolved (fixed in 2:2.10-1)
BSD
FreeBSD-SA-19:03.wpa: Multiple vulnerabilities in hostapd and wpa_supplicant
bsd_advisories·2019-05-14·CVSS 5.9
CVE-2019-11555 [MEDIUM] FreeBSD-SA-19:03.wpa: Multiple vulnerabilities in hostapd and wpa_supplicant
FreeBSD-SA-19:03.wpa Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in hostapd and wpa_supplicant
Category: contrib
Module: wpa
Announced: 2019-05-14
Affects: All supported versions of FreeBSD.
Corrected: 2019-05-01 01:42:38 UTC (stable/12, 12.0-STABLE)
2019-05-14 22:57:29 UTC (releng/12.0, 12.0-RELEASE-p4)
2019-05-01 01:43:17 UTC (stable/11, 11.2-STABLE)
2019-05-14 22:59:32 UTC (releng/11.2, 11.2-RELEASE-p10)
CVE Name: CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497,
CVE-2019-9498, CVE-2019-9499, CVE-2019-11555
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
Wi-Fi Protected Access II (WPA2) is a security protocol deve
Red Hat
wpa_supplicant: EAP-pwd cache side-channel attack
vendor_redhat·2019-04-10·CVSS 5.9
CVE-2019-9495 [MEDIUM] CWE-203 wpa_supplicant: EAP-pwd cache side-channel attack
wpa_supplicant: EAP-pwd cache side-channel attack
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
A flaw was found in wpa_supplicant. Side channel attacks were recently discovered in the SAE implementations used by b
Ubuntu
wpa_supplicant and hostapd vulnerabilities
vendor_ubuntu·2019-04-10·CVSS 7.5
CVE-2016-10743 [HIGH] wpa_supplicant and hostapd vulnerabilities
Title: wpa_supplicant and hostapd vulnerabilities
Summary: Several security issues were fixed in wpa_supplicant and hostapd.
It was discovered that wpa_supplicant and hostapd were vulnerable to a
side channel attack against EAP-pwd. A remote attacker could possibly use
this issue to recover certain passwords. (CVE-2019-9495)
Mathy Vanhoef discovered that wpa_supplicant and hostapd incorrectly
validated received scalar and element values in EAP-pwd-Commit messages. A
remote attacker could possibly use this issue to perform a reflection
attack and authenticate without the appropriate password. (CVE-2019-9497,
CVE-2019-9498, CVE-2019-9499)
It was discovered that hostapd incorrectly handled obtaining random
numbers. In rare cases where the urandom device isn't available, it would
fall back
Debian
CVE-2019-9495: wpa - The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to s...
vendor_debian·2019·CVSS 5.9
CVE-2019-9495 [MEDIUM] CVE-2019-9495: wpa - The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to s...
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
Scope: local
bookworm: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
bullseye: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
forky: resolved (fixed in 2:2.7+git201901
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
bugzilla·2019-04-12·CVSS 3.7
CVE-2019-9495 [LOW] CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack
bugzilla·2019-04-11·CVSS 5.9
CVE-2019-9495 [MEDIUM] CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack
CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack
A number of potential side channel attacks were recently discovered in the SAE implementations used by both hostapd and wpa_supplicant (see CVE-2019-9494). EAP-pwd uses a similar design for deriving PWE from the password and while a specific attack against EAP-pwd is not yet known to be tested, there is no reason to believe that the EAP-pwd implementation would be immune against the type of cache attack that was identified for the SAE implementation. Since the EAP-pwd implementation in hostapd (EAP server) and wpa_supplicant (EAP peer) does not support MODP groups, the timing attack described against SAE is not applicable for the EAP-pwd implementation.
References:
https://wpa3.mathyvanhoef.com/
https://w1.fi/security/2019-
Bugzilla
CVE-2019-9495 hostapd: wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
bugzilla·2019-04-11·CVSS 3.7
CVE-2019-9495 [LOW] CVE-2019-9495 hostapd: wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
CVE-2019-9495 hostapd: wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2019-9495 hostapd: wpa_supplicant: EAP-pwd cache side-channel attack [epel-all]
bugzilla·2019-04-11·CVSS 3.7
CVE-2019-9495 [LOW] CVE-2019-9495 hostapd: wpa_supplicant: EAP-pwd cache side-channel attack [epel-all]
CVE-2019-9495 hostapd: wpa_supplicant: EAP-pwd cache side-channel attack [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
bugzilla·2019-04-11·CVSS 3.7
CVE-2019-9495 [LOW] CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.htmlhttp://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00030.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/https://seclists.org/bugtraq/2019/May/40https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.aschttps://w1.fi/security/2019-2/https://www.synology.com/security/advisory/Synology_SA_19_16http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.htmlhttp://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00030.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/https://seclists.org/bugtraq/2019/May/40https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.aschttps://w1.fi/security/2019-2/https://www.synology.com/security/advisory/Synology_SA_19_16
2019-04-17
Published