Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-16275

22
FAUCET Score

CVE-2019-16275 is a denial-of-service vulnerability affecting hostapd and wpa_supplicant versions prior to 2.10, impacting Canonical, Debian, and w1.fi products. It allows an attacker within Wi-Fi range to send a crafted 802.11 frame, causing an incorrect disconnection indication due to mishandled source address validation, bypassing PMF protections. Rated Medium (CVSS 6.5), this vulnerability requires adjacent network access with low attack complexity and results in high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.9CPE matchmatch criteria
cpe:2.3:a:w1.fi:hostapd:*:*:*:*:*:*:*:*
<= 2.9CPE matchmatch criteria
cpe:2.3:a:w1.fi:wpa_supplicant:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.21%
Probability of exploitation in next 30 days
EPSS Percentile
65.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0121 is in the 93rd percentile among its peer group of 1,802 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

microsoftpatch availablevia msrc
Product: 17019-16820Fixed in: 2.9-2
microsoftpatch availablevia msrc
Product: 17020-16823Fixed in: 2.9-4
microsoftpatch availablevia msrc
Product: cm1 wpa_supplicant 2.9-2 on CBL Mariner 1.0Fixed in: 2.9-2
microsoftpatch availablevia msrc
Product: cbl2 wpa_supplicant 2.9-4 on CBL Mariner 2.0Fixed in: 2.9-4
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 2.9-2
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 2.9-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.9-4
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.9-4

Vendor Advisories (3)

microsoft2020-Aug/CVE-2019-16275

CVE-2019-16275

Aug 11, 2020
redhatCVE-2019-16275Moderate

wpa_supplicant: AP mode PMF disconnection protection bypass

Sep 11, 2019
microsoft2019-Sep/CVE-2019-16275Moderate

hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.

Sep 10, 2019

References

lists.debian.org / debian-lts-announce/2019/09/msg00017.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/36G4XAZ644DMHBLKOL4FDSPZVIGNQY6U
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/B7NCLOPTZNRRNYODH22BFIDH6YIQWLJD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/FEGITWRTIWABW54ANEPCEF4ARZLXGSK5
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/HY6STGJIIROVNIU6VMB2WTN2Q5M65WF4
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/PBJXUKV6XMSELWNXPS37CSUIH5EUHFXQ
seclists.org / bugtraq/2019/Sep/56
Mailing ListThird Party Advisory
usn.ubuntu.com / 4136-1
Third Party Advisory
usn.ubuntu.com / 4136-2
Third Party Advisory
w1.fi / security/2019-7
PatchVendor Advisory
w1.fi / security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt
MitigationVendor Advisory
debian.org / security/2019/dsa-4538
Third Party Advisory
openwall.com / lists/oss-security/2019/09/11/7
Mailing ListMitigationThird Party Advisory
openwall.com / lists/oss-security/2019/09/12/6
Mailing ListMitigationThird Party Advisory