CVE Vulnerabilities

CVE-2019-5062

Origin Validation Error

Published: Dec 12, 2019 | Modified: Jun 17, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of service.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Hostapd W1.fi 2.6 (including) 2.6 (including)
Wpa Ubuntu bionic *
Wpa Ubuntu disco *
Wpa Ubuntu eoan *
Wpa Ubuntu groovy *
Wpa Ubuntu hirsute *
Wpa Ubuntu impish *
Wpa Ubuntu kinetic *
Wpa Ubuntu lunar *
Wpa Ubuntu mantic *
Wpa Ubuntu trusty *
Wpa Ubuntu trusty/esm *
Wpa Ubuntu xenial *

References