CVE-2019-16275: Medium severity w1.fi hostapd vulnerability
hostapd before 2.10 and wpasupplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16275?
CVE-2019-16275 is a vulnerability that allows an incorrect indication of disconnection in hostapd and wpa_supplicant due to mishandled source address validation, leading to a denial of service.
What is the severity of CVE-2019-16275?
CVE-2019-16275 has a severity value of 6.5, which is considered medium.
Which software is affected by CVE-2019-16275?
hostapd versions before 2.10 and wpa_supplicant versions before 2.10 are affected by CVE-2019-16275.
What is the remedy for CVE-2019-16275?
To fix CVE-2019-16275, update hostapd to version 2.10 or later, and update wpa_supplicant to version 2.10 or later.
Where can I find more information about CVE-2019-16275?
You can find more information about CVE-2019-16275 on the following references: [1] [2] [3].