CVE-2019-13377
Description
EAP-pwd side-channel leak in hostapd/wpa_supplicant 2.x using Brainpool curves enables offline password recovery.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
EAP-pwd side-channel leak in hostapd/wpa_supplicant 2.x using Brainpool curves enables offline password recovery.
Vulnerability
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.9 (prior to the August 2019 updates) are vulnerable to side-channel attacks when Brainpool curves are used. Observable timing differences and cache access patterns during password element derivation can leak information to a remote attacker. This affects versions using the Brainpool P256r1, P384r1, P512r1 curves, as referenced in [1] and [2].
Exploitation
An attacker positioned on the same network as the victim (or with the ability to observe timing/cache behavior across a shared resource) can perform a side-channel attack. The attack requires no authentication and no user interaction beyond the victim connecting to the attacker's rogue AP (or the attacker connecting to a legitimate AP using EAP-pwd). The attacker passively observes the password derivation computation and uses statistical analysis over multiple sessions to recover the password. The attack does not require write access or a race condition; it is purely observational.
Impact
Successful recovery of the EAP-pwd password allows the attacker to impersonate the victim on the network, gain unauthorized access to protected resources, or compromise the confidentiality of communications. The password is used for authentication in EAP-pwd and SAE; full password recovery gives the attacker the same privileges as the legitimate user.
Mitigation
The vulnerability is fixed in hostapd 2.9 and wpa_supplicant 2.9 (and later versions), as released in Ubuntu USN-4098-1 [1] and Fedora updates [2]. Users should upgrade to these patched versions. No workarounds are available; the fix requires updating the software. The issue is also addressed in the upstream wpa_supplicant/hostapd repository.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
24- Range: >=2.0, <=2.8
- osv-coords22 versionspkg:rpm/opensuse/wpa_supplicant&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/wpa_supplicant&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/wpa_supplicant&distro=openSUSE%20Tumbleweedpkg:rpm/suse/wpa_supplicant&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/wpa_supplicant&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/wpa_supplicant&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/wpa_supplicant&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/wpa_supplicant&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 2.9-lp151.5.10.1+ 21 more
- (no CPE)range: < 2.9-lp151.5.10.1
- (no CPE)range: < 2.9-lp152.8.3.1
- (no CPE)range: < 2.9-13.4
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-4.20.1
- (no CPE)range: < 2.9-4.20.1
- (no CPE)range: < 2.9-4.20.1
- (no CPE)range: < 2.9-4.20.1
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-23.3.1
- (no CPE)range: < 2.9-4.20.1
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-23.3.1
- (no CPE)range: < 2.9-4.20.1
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-15.22.1
- (no CPE)range: < 2.9-15.22.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
6- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IELLEPIXWQOJFW4SZMU3WQHO63JFAHA4/mitrevendor-advisoryx_refsource_FEDORA
- www.debian.org/security/2019/dsa-4538mitrevendor-advisoryx_refsource_DEBIAN
- seclists.org/bugtraq/2019/Sep/56mitremailing-listx_refsource_BUGTRAQ
- usn.ubuntu.com/4098-1/mitrex_refsource_CONFIRM
- w1.fi/cgit/hostap/commit/mitrex_refsource_MISC
- w1.fi/cgit/hostap/commit/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.