CVE-2021-27803

Severity

75%

Complexity

16%

Confidentiality

98%

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.

CVSS 3.1 Base Score 7.5. CVSS Attack Vector: adjacent_network. CVSS Attack Complexity: high. CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS 2.0 Base Score 5.4. CVSS Attack Vector: adjacent_network. CVSS Attack Complexity: medium. CVSS Vector: (AV:A/AC:M/Au:N/C:P/I:P/A:P).

Overview

First reported 3 years ago

2021-02-26 23:15:00

Last updated 3 years ago

2021-04-23 00:15:00

Affected Software

Debian Linux 9.0

9.0

Fedora 32

32

References

https://w1.fi/security/2021-1/0001-P2P-Fix-a-corner-case-in-peer-addition-based-on-PD-R.patch

https://w1.fi/security/2021-1/wpa_supplicant-p2p-provision-discovery-processing-vulnerability.txt

https://www.openwall.com/lists/oss-security/2021/02/25/3

[oss-security] 20210227 Re: wpa_supplicant P2P provision discovery processing vulnerability

[debian-lts-announce] 20210302 [SECURITY] [DLA 2581-1] wpa security update

FEDORA-2021-3430f96019

[oss-security] 20210227 Re: wpa_supplicant P2P provision discovery processing vulnerability

Mailing List, Mitigation, Third Party Advisory

[debian-lts-announce] 20210302 [SECURITY] [DLA 2581-1] wpa security update

Mailing List, Third Party Advisory

FEDORA-2021-3430f96019

Mailing List, Third Party Advisory

https://w1.fi/security/2021-1/0001-P2P-Fix-a-corner-case-in-peer-addition-based-on-PD-R.patch

Patch, Vendor Advisory

https://w1.fi/security/2021-1/wpa_supplicant-p2p-provision-discovery-processing-vulnerability.txt

Vendor Advisory

https://www.openwall.com/lists/oss-security/2021/02/25/3

Mailing List, Mitigation, Third Party Advisory

FEDORA-2021-99cad2b81f

FEDORA-2021-9b00febe54

FEDORA-2021-99cad2b81f

Mailing List, Third Party Advisory

FEDORA-2021-9b00febe54

Mailing List, Third Party Advisory

https://w1.fi/security/2021-1/wpa_supplicant-p2p-provision-discovery-processing-vulnerability.txt

Mitigation, Vendor Advisory

[debian-lts-announce] 20210302 [SECURITY] [DLA 2581-1] wpa security update

Mailing List, Mailing List, Third Party Advisory

DSA-4898

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.