CVE-2022-23304
CRITICALhostapd and wpa_supplicant < 2.10 - Side-Channel Attack via EAP-pwd Cache Access Patterns
Title source: llmDescription
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
References (4)
Core 4
Core References
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPDHU5MV464CZBPX7N2SNMUYP6DFIBZL/
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202309-16
Mitigation, Patch, Third Party Advisory
https://w1.fi/security/2022-1/
Scores
CVSS v3
9.8
EPSS
0.0009
EPSS Percentile
26.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-203
Status
published
Products (3)
fedoraproject/fedora
35
w1.fi/hostapd
< 2.10
w1.fi/wpa_supplicant
< 2.10
Published
Jan 17, 2022
Tracked Since
Feb 18, 2026