#VU20415 Information disclosure in wpa_supplicant and hostapd - CVE-2019-13377
Published: August 27, 2019 / Updated: September 30, 2019
wpa_supplicant
hostapd
Jouni Malinen
Description
The vulnerability allows a remote attacker to conduct time-based side-channel attacks on a targeted system.
The vulnerability exists due to insufficient security restrictions during the WPA3's Dragonfly handshake process when using Brainpool curves. A remote in radio range of the access point can observe timing differences and cache access patterns, conduct a side-channel attack and access sensitive information that could be used for full password recovery.