Improper Authentication in wpa_supplicant and hostapd - CVE-2019-9497
Published: January 6, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. A remote attacker can complete EAP-PWD authentication without knowing the password and gain unauthorized access to the application.
However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key or complete the key exchange.
This vulnerability affects the following products:
- hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4
- hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7
Affected software
hostapd
busybox (Alpine package)
hostapd (Alpine package)
hostapd
wpa_supplicant
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
Fedora
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux
Opensuse
How to mitigate CVE-2019-9497
hostapd - update to 2.8
hostapd (Alpine package) - update to 2.7-r4
hostapd - addressed in versions 2.7-1.el7, 2.7-2.fc28, 2.7-2.fc29, 2.7-2.fc30
wpa_supplicant - update to 2.7-5.fc30
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1
External References
- http://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/
- https://seclists.org/bugtraq/2019/May/40
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.asc
- https://w1.fi/security/2019-4/
- https://www.synology.com/security/advisory/Synology_SA_19_16
Related Security Bulletins
- Multiple vulnerabilities in WPA3 hostapd and wpa_supplicant
- OpenSUSE Linux update for hostapd
- Improper Authentication in hostapd (Alpine package)
- Improper Authentication in busybox (Alpine package)
- SUSE update for wpa_supplicant
- Fedora 30 update for wpa_supplicant
- Fedora 30 update for hostapd
- Fedora 29 update for hostapd
- Fedora 28 update for hostapd
- Fedora EPEL 7 update for hostapd