Improper Authentication in wpa_supplicant and hostapd - CVE-2019-9497

 

Improper Authentication in wpa_supplicant and hostapd - CVE-2019-9497

Published: January 6, 2020


Vulnerability identifier: #VU23962
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9497
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to the implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. A remote attacker can complete EAP-PWD authentication without knowing the password and gain unauthorized access to the application.

However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key or complete the key exchange.

This vulnerability affects the following products:

  • hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4
  • hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7

Affected software

wpa_supplicant
hostapd
busybox (Alpine package)
hostapd (Alpine package)
hostapd
wpa_supplicant
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
Fedora
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux
Opensuse

How to mitigate CVE-2019-9497

Install updates from vendor's website.

wpa_supplicant - update to 2.8
hostapd - update to 2.8
hostapd (Alpine package) - update to 2.7-r4
hostapd - addressed in versions 2.7-1.el7, 2.7-2.fc28, 2.7-2.fc29, 2.7-2.fc30
wpa_supplicant - update to 2.7-5.fc30
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1

External References

Related Security Bulletins