hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LW1.fi Hostapd
APPW1.Fi≤ 2.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2022-23304CRITICAL9.8PL ✓same product
Side-channel attack w EAP-pwd w hostapd i wpa_supplicant (przed 2.10)
CVE-2022-23303CRITICAL9.8PL ✓same product
Atak side-channel na implementację SAE w hostapd i wpa_supplicant
CVE-2020-12695HIGH7.5same product
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subs...
CVE-2019-10064HIGH7.5same product
hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any...
CVE-2019-9497HIGH8.1same product
The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar an...