Denial of Service Vulnerability in WPA Supplicant by The Open Wireless Movement
CVE-2015-5315

5.9MEDIUM

Key Information:

Vendor

W1.fi

Vendor
CVE Published:
21 February 2018

What is CVE-2015-5315?

The eap_pwd_process function in the WPA Supplicant prior to version 2.6 does not adequately check the size of the reassembly buffer when handling EAP-pwd messages. This oversight can be exploited by remote attackers to send a large final fragment, resulting in process termination. This vulnerability highlights significant concerns for users configuring EAP-pwd in their network profiles, as it can lead to service interruptions.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.