CVE-2019-5062
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of service.
Published
2019-12-12T22:15:11.127
Last Modified
2024-11-21T04:44:16.487
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 6.5 (MEDIUM)
CVSSv2 Vector
AV:A/AC:L/Au:N/C:N/I:N/A:P
- Access Vector: ADJACENT_NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: NONE
- Integrity Impact: NONE
- Availability Impact: PARTIAL
Exploitability Score
6.5
Impact Score
2.9
Weaknesses
-
Type: Secondary
CWE-440
-
Type: Primary
CWE-346
Affected Vendors & Products
Type |
Vendor |
Product |
Version/Range |
Vulnerable? |
Application |
w1.fi
|
hostapd
|
2.6 |
Yes
|
References