CVE-2019-9496External Control of Critical State Data in Alliance Hostapd With SAE Support

Severity
7.5HIGHNVD
EPSS
2.4%
top 15.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 14

Description

An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Also affects: Fedora 28, 29, 30

Patches

🔴Vulnerability Details

3
GHSA
GHSA-cvwc-47mg-vx9r: An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confi2022-05-14
OSV
CVE-2019-9496: An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confi2019-04-17
CVEList
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps2019-04-17

📋Vendor Advisories

3
BSD
FreeBSD-SA-19:03.wpa: Multiple vulnerabilities in hostapd and wpa_supplicant2019-05-14
Red Hat
hostapd: SAE confirm missing state validation in hostapd/AP2019-04-10
Debian
CVE-2019-9496: wpa - An invalid authentication sequence could result in the hostapd process terminati...2019

💬Community

3
Bugzilla
CVE-2019-9496 hostapd: SAE confirm missing state validation in hostapd/AP [fedora-all]2019-04-11
Bugzilla
CVE-2019-9496 hostapd: SAE confirm missing state validation in hostapd/AP [epel-all]2019-04-11
Bugzilla
CVE-2019-9496 hostapd: SAE confirm missing state validation in hostapd/AP2019-04-11
CVE-2019-9496 — External Control of Critical State Data | cvebase