CVE-2022-23304
EUVD-2022-2838917.01.2022, 02:15
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| w1.fi | hostapd | 𝑥 < 2.10 |
| w1.fi | wpa_supplicant | 𝑥 < 2.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References