ISOMAN

CVE

CVE-2018-14526

An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00013.html
  2. http://www.securitytracker.com/id/1041438
  3. https://access.redhat.com/errata/RHSA-2018:3107
  4. https://cert-portal.siemens.com/productcert/pdf/ssa-344983.pdf
  5. https://lists.debian.org/debian-lts-announce/2018/08/msg00009.html
  6. https://papers.mathyvanhoef.com/woot2018.pdf
  7. https://security.FreeBSD.org/advisories/FreeBSD-SA-18:11.hostapd.asc
  8. https://usn.ubuntu.com/3745-1/
  9. https://w1.fi/security/2018-1/unauthenticated-eapol-key-decryption.txt
  10. https://www.us-cert.gov/ics/advisories/icsa-19-344-01
  11. http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00013.html
  12. http://www.securitytracker.com/id/1041438
  13. https://access.redhat.com/errata/RHSA-2018:3107
  14. https://cert-portal.siemens.com/productcert/pdf/ssa-344983.pdf
  15. https://lists.debian.org/debian-lts-announce/2018/08/msg00009.html
  16. https://papers.mathyvanhoef.com/woot2018.pdf
  17. https://security.FreeBSD.org/advisories/FreeBSD-SA-18:11.hostapd.asc
  18. https://usn.ubuntu.com/3745-1/
  19. https://w1.fi/security/2018-1/unauthenticated-eapol-key-decryption.txt
  20. https://www.us-cert.gov/ics/advisories/icsa-19-344-01