Table of Contents
This issue did not affect the versions of wpa_supplicant as shipped with Red Hat Enterprise Linux 5, 6 as they did not include support for EAP-pwd.
This issue did not affect the versions of wpa_supplicant as shipped with Red Hat Enterprise Linux 7 as they are not compiled with EAP-pwd enabled. In particular, the CONFIG_EAP_PWD=y option is not set at compile time.
CVSS v3 metrics
NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.
|CVSS3 Base Score||4.3|
|CVSS3 Base Metrics||CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N|
|Attack Vector||Adjacent Network|
Affected Packages State
|Red Hat Virtualization 4||rhvm-appliance||Not affected|
|Red Hat Virtualization 4||redhat-virtualization-host||Not affected|
|Red Hat Enterprise Linux 8||wpa_supplicant||Not affected|
|Red Hat Enterprise Linux 7||wpa_supplicant||Not affected|
|Red Hat Enterprise Linux 6||wpa_supplicant||Not affected|
|Red Hat Enterprise Linux 5||wpa_supplicant||Not affected|
AcknowledgementsRed Hat would like to thank Mathy Vanhoef (NYUAD) and Eyal Ronen (Tel Aviv University & KU Leuven) for reporting this issue.
CVE description copyright © 2017, The MITRE Corporation