CVE-2022-23303Critical· 9.8▾ AbyssalPoC availableThe implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 0.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.9%
2.9% → 3.1%
1 GitHub repo
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
hostapd < 2.10wpa_supplicant < 2.10fedora = 35Upgrade past the affected range:
hostapd 2.10wpa_supplicant 2.10Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-23304Critical· 9.8The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns
CVE-2022-37660Medium· 6.5In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association
CVE-2021-30004Medium· 5.3In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
CVE-2020-3585Medium· 5.3A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain ac…
CVE-2026-95270Low· 3.7A flaw has been found in dgtlmoon changedetection.io up to 0.60.7
CVE-2026-59341Medium· 4.2A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints