VulnSea

hostapd vulnerabilities

CVEs whose affected-version data names the hostapd package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2022-37660Medium· 6.5
1y ago

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another entity using PKEX in the past, will be able to subvert a future boots…

Sunlitw1.fi · hostapdEPSS 0.38%via NVD
CVE-2022-23304Critical· 9.8
4y ago

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.

Midnightw1.fi · hostapdEPSS 1.9%via NVD
CVE-2022-23303Critical· 9.8PoC
4y ago

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.

Abyssalw1.fi · hostapdEPSS 3.1%via NVD
CVE-2021-30004Medium· 5.3
5y ago

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

Sunlitw1.fi · hostapdEPSS 1.7%via NVD
hostapd vulnerabilities (CVEs) · VulnSea