Home/Product/w1.fi wpa supplicant
Product

w1.fi wpa supplicant

41 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-5290
all versions
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unpriv
8.8HIGH
CVE-2023-52160
<= 2.10
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant mu
6.5MEDIUM
CVE-2022-23304
< 2.10
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a r
9.8CRITICAL
CVE-2022-23303
< 2.10
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a resul
9.8CRITICAL
CVE-2021-30004
all versions
In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c
5.3MEDIUM
CVE-2021-27803
>= 1.0 and < 2.10
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery
7.5HIGH
CVE-2019-16275
<= 2.9
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because so
6.5MEDIUM
CVE-2019-11555
< 2.8
The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmenta
5.9MEDIUM
CVE-2019-9499
<= 2.4
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on impo
8.1HIGH
CVE-2019-9498
<= 2.4
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported
8.1HIGH
CVE-2019-9497
<= 2.4
The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in
8.1HIGH
CVE-2019-9496
<= 2.7
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when proc
7.5HIGH
CVE-2019-9495
<= 2.7
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access pa
3.7LOW
CVE-2019-9494
<= 2.7
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing d
5.9MEDIUM
CVE-2018-14526
>= 2.0 and <= 2.6
An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key
6.5MEDIUM
CVE-2015-5316
>= 2.0 and < 2.6
The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a
5.9MEDIUM
CVE-2015-5315
>= 2.0 and < 2.6
The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer i
5.9MEDIUM
CVE-2015-5314
>= 2.0 and < 2.6
The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer
5.9MEDIUM
CVE-2017-13088
all versions
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when p
5.3MEDIUM
CVE-2017-13087
all versions
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a
5.3MEDIUM
CVE-2017-13086
all versions
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDL
6.8MEDIUM
CVE-2017-13084
all versions
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the P
6.8MEDIUM
CVE-2017-13082
all versions
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Tempora
8.1HIGH
CVE-2017-13081
all versions
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK)
5.3MEDIUM
CVE-2017-13080
all versions
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowi
5.3MEDIUM
CVE-2017-13079
all versions
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK)
5.3MEDIUM
CVE-2017-13078
all versions
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowin
5.3MEDIUM
CVE-2017-13077
all versions
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-
6.8MEDIUM
CVE-2015-0210
all versions
wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle
5.9MEDIUM
CVE-2016-4476
>= 0.6.7 and <= 2.5
hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which
7.5HIGH
CVE-2015-8041
<= 2.4
Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote attackers to
CVE-2015-4146
all versions
The EAP-pwd peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not clear the L (Length) and M (More) flags bef
CVE-2015-4145
all versions
The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate a fragment is already b
CVE-2015-4144
all versions
The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long
CVE-2015-4143
all versions
The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial
CVE-2015-4142
all versions
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for
CVE-2015-4141
all versions
The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4
CVE-2015-1863
all versions
Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read me
CVE-2014-3686
all versions
wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with actio
CVE-2007-6025
<= 0.6.0
Stack-based buffer overflow in driver_wext.c in wpa_supplicant 0.6.0 and earlier allows remote attackers to cause a denial of serv
CVE-2005-0470
all versions
Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via inval
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin