hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade hostapdUpgrade wpa_supplicant | Nov 8, 2019 | Sep 12, 2019 |
| Debian | — | Upgrade wpa | Sep 17, 2019 | Sep 17, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade wpa_supplicant | Sep 28, 2020 | Sep 12, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade wpa_supplicant | Nov 28, 2019 | Sep 12, 2019 |
| Suse | — | Upgrade hostapdUpgrade wpa_supplicant-guiUpgrade wpa_supplicant | Nov 20, 2020 | Sep 12, 2019 |
| Ubuntu | — | Upgrade hostapd (Ubuntu Pro)Upgrade wpasupplicant (Ubuntu Pro)Upgrade wpasupplicantUpgrade hostapd | Sep 19, 2019 | Sep 12, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 12, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub