CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.9. It may be remotely exploitable. It may lead to a denial-of-service condition.
CVE
CVE-2015-5314
Severity
MEDIUM
CVSS
5.9
EPSS
2.25%
Original NVD Description
The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a RADIUS server and EAP-pwd is enabled in a runtime configuration, which allows remote attackers to cause a denial of service (process termination) via a large final fragment in an EAP-pwd message.
Related CVEs
Other vulnerabilities affecting the same vendor(s)