CVE-2019-9497: The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit
Last updated 25 August 2025
Other sources
The implementations of EAP-PWD in hostapd EAP Server and wpasupplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. This vulnerability may allow an attacker to complete EAP-PWD authentication without knowing the password. However, unless the crypto library does not implement additional checks for the EC point, the attacker will not be able to derive the session key or complete the key exchange. Both hostapd with SAE support and wpasupplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpasupplicant with EAP-pwd support prior to and including version 2.7 are affected.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-9497?
CVE-2019-9497 is a vulnerability in the implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer.
What is the severity of CVE-2019-9497?
The severity of CVE-2019-9497 is high, with a severity value of 8.1.
How does CVE-2019-9497 work?
CVE-2019-9497 allows an attacker to complete EAP-PWD authentication without knowing the password by not validating the scalar and element values in EAP-pwd-Commit.
Which software is affected by CVE-2019-9497?
The affected software includes hostapd EAP Server and wpa_supplicant EAP Peer, with specific versions mentioned in the vulnerability description.
Is there a fix for CVE-2019-9497?
Yes, there are specific versions and updates mentioned in the vulnerability description that provide a remedy for CVE-2019-9497.