cbcvebase.
CVE-2019-9498
published 2019-04-17

CVE-2019-9498: The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the…

PriorityP347high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.21%
80.7th percentile
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or learning the password. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianfreeradius< freeradius 3.0.17+dfsg-1.1 (bookworm)freeradius 3.0.17+dfsg-1.1 (bookworm)
debianwpa< wpa 2:2.7+git20190128+0c1e29f-4 (bookworm)wpa 2:2.7+git20190128+0c1e29f-4 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd11.0 – 11.1
freeradiusfreeradius< 3.0.193.0.19
freeradiusfreeradius>= 0 < 3.0.17+dfsg-1.13.0.17+dfsg-1.1
freeradiusfreeradius>= 0 < 3.0.17+dfsg-1.13.0.17+dfsg-1.1
freeradiusfreeradius>= 0 < 3.0.17+dfsg-1.13.0.17+dfsg-1.1
freeradiusfreeradius>= 0 < 3.0.17+dfsg-1.13.0.17+dfsg-1.1
opensusebackports_sle
opensuseleap
opensuseleap
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.