CVE-2019-9499
published 2019-04-17CVE-2019-9499: The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not…
PriorityP348high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.21%
80.6th percentile
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | freeradius | < freeradius 3.0.17+dfsg-1.1 (bookworm) | freeradius 3.0.17+dfsg-1.1 (bookworm) |
| debian | wpa | < wpa 2:2.7+git20190128+0c1e29f-4 (bookworm) | wpa 2:2.7+git20190128+0c1e29f-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | 11.0 – 11.1 | — |
| freeradius | freeradius | < 3.0.19 | 3.0.19 |
| freeradius | freeradius | >= 0 < 3.0.17+dfsg-1.1 | 3.0.17+dfsg-1.1 |
| freeradius | freeradius | >= 0 < 3.0.17+dfsg-1.1 | 3.0.17+dfsg-1.1 |
| freeradius | freeradius | >= 0 < 3.0.17+dfsg-1.1 | 3.0.17+dfsg-1.1 |
| freeradius | freeradius | >= 0 < 3.0.17+dfsg-1.1 | 3.0.17+dfsg-1.1 |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-19:03.wpa: Multiple vulnerabilities in hostapd and wpa_supplicant
bsd_advisories·2019-05-14·CVSS 5.9
CVE-2019-11555 [MEDIUM] FreeBSD-SA-19:03.wpa: Multiple vulnerabilities in hostapd and wpa_supplicant
FreeBSD-SA-19:03.wpa Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in hostapd and wpa_supplicant
Category: contrib
Module: wpa
Announced: 2019-05-14
Affects: All supported versions of FreeBSD.
Corrected: 2019-05-01 01:42:38 UTC (stable/12, 12.0-STABLE)
2019-05-14 22:57:29 UTC (releng/12.0, 12.0-RELEASE-p4)
2019-05-01 01:43:17 UTC (stable/11, 11.2-STABLE)
2019-05-14 22:59:32 UTC (releng/11.2, 11.2-RELEASE-p10)
CVE Name: CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497,
CVE-2019-9498, CVE-2019-9499, CVE-2019-11555
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
Wi-Fi Protected Access II (WPA2) is a security protocol deve
Ubuntu
wpa_supplicant and hostapd vulnerabilities
vendor_ubuntu·2019-04-10·CVSS 7.5
CVE-2016-10743 [HIGH] wpa_supplicant and hostapd vulnerabilities
Title: wpa_supplicant and hostapd vulnerabilities
Summary: Several security issues were fixed in wpa_supplicant and hostapd.
It was discovered that wpa_supplicant and hostapd were vulnerable to a
side channel attack against EAP-pwd. A remote attacker could possibly use
this issue to recover certain passwords. (CVE-2019-9495)
Mathy Vanhoef discovered that wpa_supplicant and hostapd incorrectly
validated received scalar and element values in EAP-pwd-Commit messages. A
remote attacker could possibly use this issue to perform a reflection
attack and authenticate without the appropriate password. (CVE-2019-9497,
CVE-2019-9498, CVE-2019-9499)
It was discovered that hostapd incorrectly handled obtaining random
numbers. In rare cases where the urandom device isn't available, it would
fall back
Red Hat
wpa_supplicant: EAP-pwd peer missing commit validation for scalar/element
vendor_redhat·2019-04-10·CVSS 8.1
CVE-2019-9499 [HIGH] CWE-345 wpa_supplicant: EAP-pwd peer missing commit validation for scalar/element
wpa_supplicant: EAP-pwd peer missing commit validation for scalar/element
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
A flaw was found in wpa_supplicant. An attack using invalid scalar/element values is possible against the EAP-pwd peer since hostapd and wpa_supplicant did not validate thes
Red Hat
freeradius: eap-pwd: authentication bypass via an invalid curve attack
vendor_redhat·2019-04-10·CVSS 9.8
CVE-2019-11235 [CRITICAL] CWE-345 freeradius: eap-pwd: authentication bypass via an invalid curve attack
freeradius: eap-pwd: authentication bypass via an invalid curve attack
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
A vulnerability was found in FreeRadius. An invalid curve attack allows an attacker to authenticate as any user, without knowing the password. FreeRADIUS doesn't verify whether the received elliptic curve point is valid. The highest threat from this vulnerability is to data confidentiality and integrity.
Package: freeradius (Red Hat Enterprise Linux 5) - Not affected
Package: freeradius2 (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2019-9499: wpa - The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a ...
vendor_debian·2019·CVSS 8.1
CVE-2019-9499 [HIGH] CVE-2019-9499: wpa - The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a ...
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
Scope: local
bookworm: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
bullseye: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
forky: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
sid: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
trixie: reso
Debian
CVE-2019-11235: freeradius - FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the rece...
vendor_debian·2019·CVSS 9.8
CVE-2019-11235 [CRITICAL] CVE-2019-11235: freeradius - FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the rece...
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
Scope: local
bookworm: resolved (fixed in 3.0.17+dfsg-1.1)
bullseye: resolved (fixed in 3.0.17+dfsg-1.1)
forky: resolved (fixed in 3.0.17+dfsg-1.1)
sid: resolved (fixed in 3.0.17+dfsg-1.1)
trixie: resolved (fixed in 3.0.17+dfsg-1.1)
GHSA
GHSA-qx2m-p74g-xjwh: FreeRADIUS before 3
ghsa_unreviewed·2022-05-24·CVSS 8.1
CVE-2019-11235 [HIGH] CWE-345 GHSA-qx2m-p74g-xjwh: FreeRADIUS before 3
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
GHSA
GHSA-qppx-fffq-j22m: The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do no
ghsa_unreviewed·2022-05-13
CVE-2019-9499 [HIGH] CWE-287 GHSA-qppx-fffq-j22m: The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do no
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
OSV
CVE-2019-11235: FreeRADIUS before 3
osv·2019-04-22·CVSS 9.8
CVE-2019-11235 [CRITICAL] CVE-2019-11235: FreeRADIUS before 3
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
OSV
CVE-2019-9499: The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do no
osv·2019-04-17·CVSS 8.1
CVE-2019-9499 [HIGH] CVE-2019-9499: The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do no
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
OSV
wpa vulnerabilities
osv·2019-04-10·CVSS 7.5
CVE-2019-9495 [HIGH] wpa vulnerabilities
wpa vulnerabilities
It was discovered that wpa_supplicant and hostapd were vulnerable to a
side channel attack against EAP-pwd. A remote attacker could possibly use
this issue to recover certain passwords. (CVE-2019-9495)
Mathy Vanhoef discovered that wpa_supplicant and hostapd incorrectly
validated received scalar and element values in EAP-pwd-Commit messages. A
remote attacker could possibly use this issue to perform a reflection
attack and authenticate without the appropriate password. (CVE-2019-9497,
CVE-2019-9498, CVE-2019-9499)
It was discovered that hostapd incorrectly handled obtaining random
numbers. In rare cases where the urandom device isn't available, it would
fall back to using a low-quality PRNG. This issue only affected Ubuntu
14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10
No detection rules found.
No public exploits indexed.
HackerOne
Dragonblood: Design and Implementation Flaws in WPA3 and EAP-pwd
hackerone·2020-05-05·CVSS 9.8
[CRITICAL] Dragonblood: Design and Implementation Flaws in WPA3 and EAP-pwd
Dragonblood: Design and Implementation Flaws in WPA3 and EAP-pwd
Full background information is at [our website](wpa3.mathyvanhoef.com) and detailed information can be found in our [research paper](https://eprint.iacr.org/2019/383).
# Vulnerability Summary
## First Disclosure
Summarized, the Dragonfly handshake of WPA3 and EAP-pwd is supposed to prevent dictionary attacks. However, we discovered design flaws that still enable an adversary to perform dictionary attacks. In particular, we discovered the following design flaws in WPA3 and EAP-pwd:
- Against EAP-pwd, a timing leak exists for all supported elliptic curves. An adversary within range of the victim can induce clients to connect to the adversary's Access Point (AP) and exploit this timing leak. The leaked information can be use
Bugzilla
CVE-2019-9499 wpa_supplicant: EAP-pwd peer missing commit validation for scalar/element
bugzilla·2019-04-12·CVSS 8.1
CVE-2019-9499 [HIGH] CVE-2019-9499 wpa_supplicant: EAP-pwd peer missing commit validation for scalar/element
CVE-2019-9499 wpa_supplicant: EAP-pwd peer missing commit validation for scalar/element
An attack using invalid scalar/element values is possible against the EAP-pwd peer since hostapd and wpa_supplicant did not validate these values in the received EAP-pwd-Commit messages.When processing an EAP-pwd Commit frame, the server's scalar and element (elliptic curve point) were not validated. This allowed an adversary to bypass authentication, and act as a rogue Access Point (AP) if the crypto implementation did not verify the validity of the EC point.
The vulnerability is only exploitable if OpenSSL version 1.0.2 or lower is used, or if LibreSSL or wolfssl is used. Newer versions of OpenSSL (and also BoringSSL) implicitly validate the elliptic curve point in EC_POINT_set_affine_coordinates_GF
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00030.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/https://seclists.org/bugtraq/2019/May/40https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.aschttps://w1.fi/security/2019-4/https://www.synology.com/security/advisory/Synology_SA_19_16http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00030.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/https://seclists.org/bugtraq/2019/May/40https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.aschttps://w1.fi/security/2019-4/https://www.synology.com/security/advisory/Synology_SA_19_16
2019-04-17
Published