Lucene search

K
cve[email protected]CVE-2015-4141
HistoryJun 15, 2015 - 3:59 p.m.

CVE-2015-4141

2015-06-1515:59:05
CWE-119
web.nvd.nist.gov
124
wps
upnp
hostapd
wpa_supplicant
denial of service
crash
cve-2015-4141

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.4 Medium

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.7%

The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.

Affected configurations

NVD
Node
w1.fiwpa_supplicantMatch0.7.0
OR
w1.fiwpa_supplicantMatch0.7.1
OR
w1.fiwpa_supplicantMatch0.7.2
OR
w1.fiwpa_supplicantMatch0.7.3
OR
w1.fiwpa_supplicantMatch1.0
OR
w1.fiwpa_supplicantMatch1.1
OR
w1.fiwpa_supplicantMatch2.0
OR
w1.fiwpa_supplicantMatch2.1
OR
w1.fiwpa_supplicantMatch2.2
OR
w1.fiwpa_supplicantMatch2.3
OR
w1.fiwpa_supplicantMatch2.4
Node
w1.fihostapdMatch0.7.0
OR
w1.fihostapdMatch0.7.1
OR
w1.fihostapdMatch0.7.2
OR
w1.fihostapdMatch0.7.3
OR
w1.fihostapdMatch1.0
OR
w1.fihostapdMatch1.1
OR
w1.fihostapdMatch2.0
OR
w1.fihostapdMatch2.1
OR
w1.fihostapdMatch2.2
OR
w1.fihostapdMatch2.3
OR
w1.fihostapdMatch2.4
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.4 Medium

AI Score

Confidence

High

0.028 Low

EPSS

Percentile

90.7%