Security Advisory

CVE-2019-9494

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-04-17 13:31:08
Last updated 2024-08-04 21:54:44
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.