CVE-2019-10064 is a high-severity vulnerability affecting hostapd versions prior to 2.6 when operating in EAP mode, specifically impacting Debian Linux distributions. The flaw stems from the inappropriate use of deterministic values due to rand() and random() calls without prior seeding, leading to predictable outputs. This vulnerability has a CVSS score of 7.5 (High) and could allow an unauthenticated attacker to cause a denial of service, though it does not impact confidentiality or integrity. There is currently no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6CPE matchmatch criteria | cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.