Use of a broken or risky cryptographic algorithm in wpa_supplicant and hostapd - CVE-2022-23304

 

Use of a broken or risky cryptographic algorithm in wpa_supplicant and hostapd - CVE-2022-23304

Published: January 19, 2022


Vulnerability identifier: #VU59838
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23304
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information on the target system.

The vulnerability exists due to the implementations of EAP-PWD are vulnerable to side-channel attacks as a result of cache access patterns. A remote attacker with ability to install and execute applications can crack weak passwords when memory access patterns are visible in a shared cache.

Note, this vulnerability exists due to incomplete fix for #VU23960 (CVE-2019-9495).


Affected software

wpa_supplicant
hostapd
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openEuler
Ubuntu
Fedora
ESP-IDF
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
wpa_supplicant-gui
wpa_supplicant-help
wpa_supplicant
wpasupplicant (Ubuntu package)
hostapd (Ubuntu package)
net-wireless/hostapd
hostapd

How to mitigate CVE-2022-23304

Install updates from vendor's website.

wpa_supplicant - update to 2.10
hostapd - update to 2.10
ESP-IDF - update to 4.3.5
wpa_supplicant-debuginfo - update to 2.6-30
wpa_supplicant-debugsource - update to 2.6-30
wpa_supplicant-gui - update to 2.6-30
wpa_supplicant-help - update to 2.6-30
wpa_supplicant - update to 2.6-30
wpasupplicant (Ubuntu package) - addressed in versions 2:2.9-1ubuntu4.6, 2:2.10-6ubuntu2.2, 2:2.10-21ubuntu0.2, 2:2.10-22ubuntu0.1
hostapd (Ubuntu package) - addressed in versions 2:2.9-1ubuntu4.6, 2:2.10-6ubuntu2.2, 2:2.10-21ubuntu0.2, 2:2.10-22ubuntu0.1
wpa_supplicant-debugsource - addressed in versions 2.9-4.33.1, 2.9-15.22.1, 2.9-23.15.1
wpa_supplicant - addressed in versions 2.9-4.33.1, 2.9-15.22.1, 2.9-23.15.1
wpa_supplicant-debuginfo - addressed in versions 2.9-4.33.1, 2.9-15.22.1, 2.9-23.15.1
net-wireless/hostapd - update to 2.10
hostapd - update to 2.10-3.fc35

External References

Related Security Bulletins