CVE Vulnerabilities

CVE-2021-27803

Published: Feb 26, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5.4 MEDIUM
AV:A/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.

Affected Software

Name Vendor Start Version End Version
Wpa_supplicant W1.fi 1.0 (including) 2.10 (excluding)
Wpa Ubuntu bionic *
Wpa Ubuntu devel *
Wpa Ubuntu focal *
Wpa Ubuntu groovy *
Wpa Ubuntu trusty *
Wpa Ubuntu trusty/esm *
Wpa Ubuntu upstream *
Wpa Ubuntu xenial *
Red Hat Enterprise Linux 7 RedHat wpa_supplicant-1:2.6-12.el7_9.2 *
Red Hat Enterprise Linux 8 RedHat wpa_supplicant-1:2.9-2.el8_3.1 *
Red Hat Enterprise Linux 8.1 Extended Update Support RedHat wpa_supplicant-1:2.7-2.el8_1.1 *
Red Hat Enterprise Linux 8.2 Extended Update Support RedHat wpa_supplicant-1:2.9-2.el8_2.1 *

References