AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-5314

MEDIUM · CVSS 5.9 EPSS 2.25%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-02-21 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.9. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2015-5314
Severity
MEDIUM
CVSS
5.9
EPSS
2.25%

Original NVD Description

The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a RADIUS server and EAP-pwd is enabled in a runtime configuration, which allows remote attackers to cause a denial of service (process termination) via a large final fragment in an EAP-pwd message.

Related CVEs

Other vulnerabilities affecting the same vendor(s)