Use of a broken or risky cryptographic algorithm in wpa_supplicant and hostapd - CVE-2019-9495

 

Use of a broken or risky cryptographic algorithm in wpa_supplicant and hostapd - CVE-2019-9495

Published: January 6, 2020


Vulnerability identifier: #VU23960
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9495
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information on the target system.

The vulnerability exists due to the implementations of EAP-PWD are vulnerable to side-channel attacks as a result of cache access patterns. A remote attacker with ability to install and execute applications can crack weak passwords when memory access patterns are visible in a shared cache.


Affected software

wpa_supplicant
hostapd
hostapd (Alpine package)
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
wpa_supplicant-gui
wpa_supplicant-help
wpa_supplicant
hostapd
FortiOS
Fedora
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux
Opensuse
openEuler
FortiAP-S
FortiAP-W2

How to mitigate CVE-2019-9495

Install updates from vendor's website.

wpa_supplicant - update to 2.8
hostapd - update to 2.8
hostapd (Alpine package) - update to 2.7-r4
FortiOS - update to 6.2.2
FortiAP-S - update to 6.2.1
FortiAP-W2 - update to 6.2.1
wpa_supplicant-debuginfo - update to 2.6-30
wpa_supplicant-debugsource - update to 2.6-30
wpa_supplicant-gui - update to 2.6-30
wpa_supplicant-help - update to 2.6-30
wpa_supplicant - update to 2.6-30
hostapd - addressed in versions 2.7-1.el7, 2.7-2.fc28, 2.7-2.fc29, 2.7-2.fc30
wpa_supplicant - update to 2.7-5.fc30
wpa_supplicant-debugsource - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant - update to 2.9-15.22.1

External References

Related Security Bulletins