Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
hostapd和wpa_supplicant 信息泄露漏洞
Vulnerability Description
hostapd是一款访问点和身份验证服务器的用户空间守护程序。wpa_supplicant是一款跨平台的WPA请求程序。该程序支持WEP、WPA和WPA2等。 hostapd和wpa_supplicant 2.x至2.8版本中的SAE和EAP-pwd的实现存在安全漏洞。攻击者可利用该漏洞获取泄露的信息,进而恢复完整的密码。
CVSS Information
N/A
Vulnerability Type
N/A