CVE Vulnerabilities

CVE-2019-16275

Origin Validation Error

Published: Sep 12, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Hostapd W1.fi * 2.9 (including)
Wpa_supplicant W1.fi * 2.9 (including)
Wpa Ubuntu bionic *
Wpa Ubuntu devel *
Wpa Ubuntu disco *
Wpa Ubuntu trusty *
Wpa Ubuntu trusty/esm *
Wpa Ubuntu xenial *
Wpasupplicant Ubuntu trusty *

References