suse · CVE-2019-9499

Quick triage

Priority: high Published: 2021-05-30 14:25:42 UTC Updated: 2026-03-05 06:22:21 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-9499 severity important: SUSE including 26 source package names (hostapd-2.9-6.2, hostapd-2.9-bp150.15.1, …), 88 product×package rows across 83 product lines (Container rancher/elemental-teal-rt/5.3, Container rancher/elemental-teal-rt/5.4, … (83 product lines)): Fixed 72, Known Not Affected 16.

Description:

The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.

cvelogic Threat Intelligence