CVE-2022-23304

Description

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. The highest threat from this vulnerability is to availability, confidentiality and integrity.

Statement

Red Hat believes this vulnerability to be of moderate impact because one of the requisites for exploitation is the ability to run unprivileged code on the victim's machine; furthermore, the complexity of this attack is high, as it requires the ability to analyze cache access patterns and combine this with a sufficient number of handshake instances and an offline dictionary attack.

It is important to note that this CVE was filed as the preceding CVE-2019-9495, which was intended to address several potential side channel attacks present in wpa_supplicant, was found to be a partial fix and did not address the cache-based attack mentioned in this CVE.

In RHEL-8, the vulnerable configurations of wpa_supplicant and hostapd with SAE and EAP-pwd support (CONFIG_SAE=y and CONFIG_EAP_PWD=y, respectively) are not compiled.

In RHEL-9, no vulnerable versions of wpa_supplicant are built (versions prior to 2.10), meaning that it is not susceptible to this vulnerability.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score79.8N/A
Attack VectorLocalNetworkN/A
Attack ComplexityHighLowN/A
Privileges RequiredLowNoneN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityHighHighN/A
Integrity ImpactHighHighN/A
Availability ImpactHighHighN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Integrity,Confidentiality

Technical Impact: Gain Privileges or Assume Identity

If an attackers can spoof the endpoint, the attacker gains all the privileges that were intended for the original endpoint.

Frequently Asked Questions

Want to get errata notifications? Sign up here.