CVE-2019-5061
Last modified
CVE-2019-5061 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby Aps of the same wireless infrastructure. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby Aps of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| W1.Fi | Hostapd | 2.6 |
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0849Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0849Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5061?
How severe is CVE-2019-5061?
How do I fix CVE-2019-5061?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5054An exploitable denial-of-service vulnerability exists in the…7.5
- CVE-2019-5055An exploitable denial-of-service vulnerability exists in the…7.5
- CVE-2019-5057An exploitable code execution vulnerability exists in the PC…8.8
- CVE-2019-5058An exploitable code execution vulnerability exists in the XC…8.8
- CVE-2019-5059An exploitable code execution vulnerability exists in the XP…8.8
- CVE-2019-5060An exploitable code execution vulnerability exists in the XP…8.8
- CVE-2019-5062An exploitable denial-of-service vulnerability exists in the…6.5
- CVE-2019-5063An exploitable heap buffer overflow vulnerability exists in …8.8
- CVE-2019-5064An exploitable heap buffer overflow vulnerability exists in …8.8
- CVE-2019-5065An exploitable information disclosure vulnerability exists i…5.3
- CVE-2019-5066An exploitable use-after-free vulnerability exists in the wa…9.8
- CVE-2019-5067An uninitialized memory access vulnerability exists in the w…9.8
Are you affected by CVE-2019-5061?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
