CVE-2014-3686: Input Validation
Jouni Malinen discovered that a string supplied from a remote device could be supplied to a system() call in wpacli or hostapdcli when running an action script (with the "-a" option), resulting in arbitrary command execution. This issue could also be triggered by an attacker within radio range.
Patches are available from the following:
http://w1.fi/security/2014-1/
Based on the information about affected configurations in the upstream advisory, Red Hat Enterprise Linux 5 is likely to be not vulnerable, but Red Hat Enterprise Linux 6 and 7 are likely to be vulnerable.
Acknowledgements:
Red Hat would like to thank Jouni Malinen for reporting this issue.
References:
http://w1.fi/security/2014-1/ http://www.openwall.com/lists/oss-security/2014/10/09/28
Other sources
wpasupplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpacli or hostapdcli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3686?
CVE-2014-3686 has a severity level that indicates it allows for arbitrary command execution due to improper handling of string input.
How do I fix CVE-2014-3686?
To fix CVE-2014-3686, upgrade to wpa_supplicant version 2.3 or hostapd version 2.3, or the respective patched versions for affected software.
Which software is affected by CVE-2014-3686?
CVE-2014-3686 affects versions of wpa_supplicant up to 2.3 and hostapd up to 2.3 from Red Hat, as well as several versions of both from w1.fi and Debian.
Can CVE-2014-3686 be exploited remotely?
Yes, CVE-2014-3686 can be exploited by an attacker within radio range, leading to potential command execution on vulnerable systems.
What are the potential consequences of CVE-2014-3686?
The potential consequences of CVE-2014-3686 include unauthorized command execution, which could compromise system integrity and security.