Permissions, Privileges, and Access Controls in hostapd and wpa_supplicant - CVE-2019-9499

 

Permissions, Privileges, and Access Controls in hostapd and wpa_supplicant - CVE-2019-9499

Published: January 6, 2020


Vulnerability identifier: #VU23964
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9499
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to the implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. A remote attacker can complete authentication, session key and control of the data connection with a client.

This vulnerability affects the following products:

  • hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4
  • hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7

Affected software

hostapd
wpa_supplicant
busybox (Alpine package)
hostapd (Alpine package)
hostapd
wpa_supplicant
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
Fedora
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux
Opensuse

How to mitigate CVE-2019-9499

Install updates from vendor's website.

hostapd - update to 2.8
wpa_supplicant - update to 2.8
hostapd (Alpine package) - update to 2.7-r4
hostapd - addressed in versions 2.7-1.el7, 2.7-2.fc28, 2.7-2.fc29, 2.7-2.fc30
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1

External References

Related Security Bulletins