Skip to main content

Vendor/product archive

w1.fi / wpa_supplicant CVEs

Beta · best-effort

39 CVEs tagged to w1.fi / wpa_supplicant2 Critical, 8 High, 28 Medium, 1 Low, 0 Unrated.

CVE-2019-11555

Published Apr 26, 2019

The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where a…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9495

Published Apr 17, 2019

The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplican…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2015-5316

Published Feb 21, 2018

The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote att…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5315

Published Feb 21, 2018

The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pw…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5314

Published Feb 21, 2018

The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13088

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sle…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2017-13087

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Res…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2017-13086

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio ra…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2017-13084

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within rad…

CVSS 6.8 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2017-13082

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT)…

CVSS 8.1 · High
evidence mentions
5
Buzz score
25.9

CVE-2017-13081

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attac…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2017-13080

Published Oct 17, 2017

Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frame…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
27.3
Showing 1-25 of 39 CVEsPage 1 of 2