Information disclosure in hostapd and wpa_supplicant - CVE-2019-9494

 

Information disclosure in hostapd and wpa_supplicant - CVE-2019-9494

Published: January 6, 2020


Vulnerability identifier: #VU23959
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9494
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the implementations of SAE are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. A remote attacker can gain leaked information from a side channel attack that can be used for full password recovery.


Affected software

hostapd
wpa_supplicant
hostapd (Alpine package)
wpa_supplicant
wpa_supplicant-help
wpa_supplicant-gui
wpa_supplicant-debugsource
wpa_supplicant-debuginfo
hostapd
freeradius-mysql
python2-freeradius
freeradius-utils
freeradius-sqlite
freeradius-postgresql
freeradius-perl
freeradius-ldap
freeradius-krb5
freeradius-help
freeradius-devel
freeradius-debugsource
freeradius-debuginfo
freeradius
ESP-IDF
FortiOS
Fedora
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux
Opensuse
openEuler
FortiAP-W2
FortiAP-S

How to mitigate CVE-2019-9494

Install updates from vendor's website.

hostapd - update to 2.8
wpa_supplicant - update to 2.8
hostapd (Alpine package) - update to 2.7-r4
ESP-IDF - update to 4.3.5
FortiOS - update to 6.2.2
FortiAP-W2 - update to 6.2.1
FortiAP-S - update to 6.2.1
wpa_supplicant - update to 2.6-30
wpa_supplicant-help - update to 2.6-30
wpa_supplicant-gui - update to 2.6-30
wpa_supplicant-debugsource - update to 2.6-30
wpa_supplicant-debuginfo - update to 2.6-30
hostapd - addressed in versions 2.7-1.el7, 2.7-2.fc28, 2.7-2.fc29, 2.7-2.fc30
wpa_supplicant - update to 2.7-5.fc30
wpa_supplicant-debugsource - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant - update to 2.9-15.22.1
freeradius-mysql - update to 3.0.15-21
python2-freeradius - update to 3.0.15-21
freeradius-utils - update to 3.0.15-21
freeradius-sqlite - update to 3.0.15-21
freeradius-postgresql - update to 3.0.15-21
freeradius-perl - update to 3.0.15-21
freeradius-ldap - update to 3.0.15-21
freeradius-krb5 - update to 3.0.15-21
freeradius-help - update to 3.0.15-21
freeradius-devel - update to 3.0.15-21
freeradius-debugsource - update to 3.0.15-21
freeradius-debuginfo - update to 3.0.15-21
freeradius - update to 3.0.15-21

External References

Related Security Bulletins