CVE-2019-9496 is a denial-of-service vulnerability affecting hostapd and wpa_supplicant versions with SAE support, including those in Fedora, where an invalid authentication sequence can terminate the hostapd process. This high-severity vulnerability (CVSS 7.5) allows unauthenticated attackers to remotely disrupt service with low complexity. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for a denial-of-service attack remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.7CPE matchmatch criteria | cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:* | ||
<= 2.7CPE matchmatch criteria | cpe:2.3:a:w1.fi:wpa_supplicant:*:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.