CVE-2019-9496

CVE-2019-9496: An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps

Vendor Wi-Fi Alliance
Product hostapd with SAE support
Weakness CWE-642
Published April 17, 2019
Last update August 4, 2024

CVSS base score

What the vulnerability does

01Description

An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

Key dates

02Disclosure timeline

April 17, 2019 CVE published
August 4, 2024 Record updated