cbcvebase.
CVE-2019-9498
published 2019-04-17

CVE-2019-9498: The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the…

PriorityP347high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.21%
81.9th percentile
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or learning the password. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux——
canonicalubuntu_linux——
canonicalubuntu_linux——
debiandebian_linux——
debianfreeradius< freeradius 3.0.17+dfsg-1.1 (bookworm)freeradius 3.0.17+dfsg-1.1 (bookworm)
debianwpa< wpa 2:2.7+git20190128+0c1e29f-4 (bookworm)wpa 2:2.7+git20190128+0c1e29f-4 (bookworm)
fedoraprojectfedora——
fedoraprojectfedora——
fedoraprojectfedora——
freebsdfreebsd——
freebsdfreebsd——
freebsdfreebsd11.0 – 11.1—
freeradiusfreeradius< 3.0.193.0.19
freeradiusfreeradius>= 0 < 3.0.17+dfsg-1.13.0.17+dfsg-1.1
freeradiusfreeradius>= 0 < 3.0.17+dfsg-1.13.0.17+dfsg-1.1
freeradiusfreeradius>= 0 < 3.0.17+dfsg-1.13.0.17+dfsg-1.1
freeradiusfreeradius>= 0 < 3.0.17+dfsg-1.13.0.17+dfsg-1.1
opensusebackports_sle——
opensuseleap——
opensuseleap——
redhatenterprise_linux——
redhatenterprise_linux_eus——
redhatenterprise_linux_server——
redhatenterprise_linux_server_aus——
redhatenterprise_linux_server_tus——

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.