Improper Authentication in hostapd - CVE-2019-9496
Published: January 6, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing state validation steps when processing the
SAE confirm message when in hostapd/AP mode. A remote attacker can bypass authentication process, force the hostapd process to terminate and perform a denial of service (DoS) attack on the target system.
Affected software
busybox (Alpine package)
hostapd (Alpine package)
firefox-esr (Alpine package)
hostapd
wpa_supplicant
ESP-IDF
FortiAP-S
FortiAP-W2
Meru AP
Meru Controller
FortiOS
Fedora
SUSE Linux
Opensuse
How to mitigate CVE-2019-9496
hostapd (Alpine package) - update to 2.6-r3
ESP-IDF - update to 4.3.5
FortiAP-S - update to 6.2.2
FortiAP-W2 - update to 6.2.2
FortiOS - update to 6.2.3
Meru AP - update to 8.5.1
Meru Controller - update to 8.5.1
hostapd - addressed in versions 2.7-1.el7, 2.7-2.fc28, 2.7-2.fc29, 2.7-2.fc30
wpa_supplicant - update to 2.7-5.fc30
External References
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/
- https://seclists.org/bugtraq/2019/May/40
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.asc
- https://w1.fi/security/2019-3/
- https://www.synology.com/security/advisory/Synology_SA_19_16
Related Security Bulletins
- Multiple vulnerabilities in WPA3 hostapd and wpa_supplicant
- Improper Authentication in Fortinet WiFi WPA3 standard implementation for FortiOS and FortiAP-S/W2
- OpenSUSE Linux update for hostapd
- Improper Authentication in hostapd (Alpine package)
- Improper Authentication in busybox (Alpine package)
- Improper Authentication in firefox-esr (Alpine package)
- Multiple vulnerabilities in ESP-IDF
- Fedora 30 update for wpa_supplicant
- Fedora 30 update for hostapd
- Fedora 29 update for hostapd
- Fedora 28 update for hostapd
- Fedora EPEL 7 update for hostapd